I'm working on a custom provider that works exactly like a classical user form, however I have to give a second parameter to identify the user: a websiteId (I'm creating a dynamic website plateform).
So a username is no more unique, but the combinaison of username and websiteId it is.
I successfully created my custom authentication, the last problem I have is to get the websiteId from the domain thanks to a listener, it works, but infortunately the method that get the website id from the domain is loaded after my authentication provider, so I can't get the websiteId in time :(
I tried to change the listener priority (test 9999, 1024, 255 and 0, and negative numbers -9999, -1024, -255 etc...), in vain, it's loaded always after.
Here my code:
# Listeners _________________
class: Sybio\Bundle\WebsiteBundle\Services\Listener\WebsiteListener
- @doctrine
- @sybio.website_manager
- @translator
- %sybio.states%
- { name: kernel.event_listener, event: kernel.request, method: onDomainParse, priority: 255 }
# Security _________________
class: Sybio\Bundle\WebsiteBundle\Security\Authentication\Provider\WebsiteUserProvider
arguments: [@website_listener, @doctrine.orm.entity_manager]
My listener is "website_listener", and you can see i use it for my sybio_website.user_provider as argument.
// ...
class WebsiteListener extends Controller
protected $doctrine;
protected $websiteManager;
protected $translator;
protected $websiteId;
* @var array
protected $entityStates;
public function __construct($doctrine, $websiteManager, $translator, $entityStates)
$this->doctrine = $doctrine;
$this->websiteManager = $websiteManager;
$this->translator = $translator;
$this->entityStates = $entityStates;
* @param Event $event
public function onDomainParse(Event $event)
$request = $event->getRequest();
$website = $this->websiteManager->findOne(array(
'domain' => $request->getHost(),
'state' => $this->entityStates['website']['activated'],
if (!$website) {
throw $this->createNotFoundException($this->translator->trans('page.not.found'));
$this->websiteId = $website->getId();
* @param integer $websiteId
public function getWebsiteId()
return $this->websiteId;
$websiteId is hydrated, not in time as you will see in my provider...
namespace Sybio\Bundle\WebsiteBundle\Security\Authentication\Provider;
// ...
class WebsiteUserProvider implements UserProviderInterface
private $em;
private $websiteId;
private $userEntity;
public function __construct($websiteListener, EntityManager $em)
$this->em = $em;
$this->websiteId = $websiteListener->getWebsiteId(); // Try to get the website id from my listener, but it's method onDomainParse is not called in time
$this->userEntity = 'Sybio\Bundle\CoreBundle\Entity\User';
public function loadUserByUsername($username)
// I need the websiteId here to identify the user by its username and the website:
if ($user = $this->findUserBy(array('username' => $username, 'website' => $this->websiteId))) {
return $user;
throw new UsernameNotFoundException(sprintf('No record found for user %s', $username));
// ...
So any idea will be appreciate ;) I spent a lot of time to set up my authentication configuration, but now I can't get the websiteId in time, too bad :(
Thanks for your anwsers !
I had also other files of my authentication system to understand, I don't think I can control the provider position when loading, because they're witten in the security.yml config:
// ...
class WebsiteAuthenticationProvider extends UserAuthenticationProvider
private $encoderFactory;
private $userProvider;
* @param \Symfony\Component\Security\Core\User\UserProviderInterface $userProvider
* @param UserCheckerInterface $userChecker
* @param $providerKey
* @param EncoderFactoryInterface $encoderFactory
* @param bool $hideUserNotFoundExceptions
public function __construct(UserProviderInterface $userProvider, UserCheckerInterface $userChecker, $providerKey, EncoderFactoryInterface $encoderFactory, $hideUserNotFoundExceptions = true)
parent::__construct($userChecker, $providerKey, $hideUserNotFoundExceptions);
$this->encoderFactory = $encoderFactory;
$this->userProvider = $userProvider;
* {@inheritdoc}
protected function retrieveUser($username, UsernamePasswordToken $token)
$user = $token->getUser();
if ($user instanceof UserInterface) {
return $user;
try {
$user = $this->userProvider->loadUserByUsername($username);
if (!$user instanceof UserInterface) {
throw new AuthenticationServiceException('The user provider must return a UserInterface object.');
return $user;
} catch (UsernameNotFoundException $notFound) {
throw $notFound;
} catch (\Exception $repositoryProblem) {
throw new AuthenticationServiceException($repositoryProblem->getMessage(), $token, 0, $repositoryProblem);
// ...
The factory:
// ...
class WebsiteFactory extends FormLoginFactory
public function getKey()
return 'website_form_login';
protected function getListenerId()
return 'security.authentication.listener.form';
protected function createAuthProvider(ContainerBuilder $container, $id, $config, $userProviderId)
$provider = 'security.authentication_provider.sybio_website.'.$id;
->setDefinition($provider, new DefinitionDecorator('security.authentication_provider.sybio_website'))
->replaceArgument(0, new Reference($userProviderId))
->replaceArgument(2, $id)
return $provider;
SybioWebsiteBundle (dependency):
// ...
class SybioWebsiteBundle extends Bundle
public function build(ContainerBuilder $container)
$extension = $container->getExtension('security');
$extension->addSecurityListenerFactory(new WebsiteFactory());
provider: website_provider
pattern: ^/
anonymous: ~
login_path: /login.html
check_path: /login
path: /logout.html
target: /
id: sybio_website.user_provider
As you can see in the SecurityExtension.php The factories used do not have any sort of priority system. It just adds your factory to the end of the array, that's it. Therefore it is impossible to put your custom authentication before that of symfony's security component.
An option may be to override the DaoAuthenticationProvider class paramater with your class. I hope that symfony2 will change from factories to a registry where you can add your custom authentication with a tag and a priority because this is not open/closed enough for me.
Firewall::onKernelRequest is registered with a priority of 8 (sf2.2). A priority of 9 should ensure that your listener is called first (works for me).
I had a similar problem, which was to create subdomain-specific "Campaign" sites within a single sf2.2 app: {campaign}.{domain} . Every User has many Campaigns and I, like you, wanted to prevent a User without the given Campaign from logging in.
My solution was to create a Doctrine filter to add my campaign criteria to every relevant query made under {campaign}.{domain}. A kernel.request listener (with priority 9!) is responsible for activating the filter before my generic user provider tries to loadUserByUsername. I use mongodb, but the idea is similar for ORM.
The best part is that I'm still using stock authentication classes. This is basically all there is to it:
class: My\Filter\CampaignFilter
enabled: false
class CampaignFilter extends BsonFilter
public function addFilterCriteria(ClassMetadata $targetMetadata)
$class = $targetMetadata->name;
$campaign = $this->parameters['campaign'];
$campaign = $campaign instanceof Campaign ? $campaign->getId() : $campaign;
if ($targetMetadata->hasField('campaign')) {
return array('campaign' => $this->parameters['campaign']);
if ($targetMetadata->hasField('campaigns')) {
return array('campaigns' => $this->parameters['campaign']);
return array();
My listener is declared as:
<service id="my.campaign_listener" class="My\EventListener\CampaignListener">
<tag name="kernel.event_listener" event="kernel.request" method="onKernelRequest" priority="9" />
<argument type="service" id="doctrine.odm.mongodb.document_manager" />
The listener class:
class CampaignListener
private $dm;
public function __construct(DocumentManager $dm)
$this->dm = $dm;
public function onKernelRequest(GetResponseEvent $event)
if (HttpKernelInterface::MASTER_REQUEST != $event->getRequestType()) {
$request = $event->getRequest();
if ($campaign = $request->attributes->get('campaign', false)) {
$filters = $this->dm->getFilterCollection();
$filter = $filters->enable('campaign');
$filter->setParameter('campaign', $campaign);
'campaign' is available in the request here thanks to my routing configuration:
resource: "@My/Controller/CampaignController.php"
type: annotation
host: "{campaign}.{domain}"
campaign: test
domain: %domain%
domain: %domain%
.. and %domain% is a parameter from config.yml or config_dev.yml
Like the response provide by benki07 it's a question of prority, you have to put your listener before the Firewall::onKernelRequest
Then, your listener will be called -> Firewall is call and your authentification listener are called with the webSiteId registered.
