I'm learning how to use the Symfony Security Bundle with a JSON-Login.
Therefore I've been following the official guide: https://symfony.com/doc/current/security.html#json-login
Interestingly, after getting authenticated, I do not need to send the generated token at all. It rather seems to remember me by Session-Cookie.
$this->denyAccessUnlessGranted('IS_AUTHENTICATED_FULLY');
As a beginner, I've got following questions:
- Is this a reasonable behavior, given you are using a REST API to authenticate?
- If I would use a token, what would be an acceptable way of creating it? Can I just provide a UID?