form-types-validation · git:20260917.3d83f4c · 2026-09-17 · sha256 2541006508668231

form-types-validation git:20260917.3d83f4cA

Immutable. This exact content is served forever at /api/v1/blob/2541006508668231.

---
name: form-types-validation
description: Build Symfony forms with custom Form Types, validation constraints, HTTP 422 handling, and multi-step flows
capabilities: [read, search, edit, shell]
tags: [security]
# projected by `bun run build` — do not edit by hand
allowed-tools:
  - Read
  - Glob
  - Grep
  - Write
  - Edit
  - Bash
---

# Form Types Validation (Symfony)

## Use when
- Hardening access-control or validation boundaries.
- Aligning voters/security expressions with domain rules.

## Default workflow
1. Map actor/resource/action decision matrix.
2. Implement voter/constraint logic at the right boundary.
3. Wire checks at controllers and API operations.
4. Test allowed/forbidden/invalid paths comprehensively.

## Guardrails
- Avoid policy logic duplication across layers.
- Do not leak privileged state via error detail.
- Preserve explicit deny behavior for sensitive actions.

## Progressive disclosure
- Use this file for execution posture and risk controls.
- Open references when deep implementation details are needed.

## Output contract
- Security boundary updates.
- Integration points enforcing decisions.
- Negative-path test results.

## References
- `reference.md`
- `docs/complexity-tiers.md`