# see https://symfony.com/doc/current/reference/configuration/framework.html framework: secret: '%env(APP_SECRET)%' trusted_proxies: 'private_ranges' trusted_headers: ['x-forwarded-for', 'x-forwarded-host', 'x-forwarded-proto'] # Sessions are disabled — preauth implements its own cookie/cache-based # session management and does not use Symfony's session subsystem. session: false