access_control:
- { path: ^/login, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/logout, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/register, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/recover-password, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/activate-account, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/, roles: ROLE_USER }
似乎 access_control 可以很好地限制不同角色的访问,但我需要类似.IS_AUTHENTICATED_ANONYMOUSLY
only
&& ! ROLE_USER && ! ROLE_ADMIN
我不希望它已经登录以允许访问此路线。如果这是可能的,security.yml
那就太好了。