symfony/http-foundation
57.6
Adequate · 26 September 2026
12.5k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is the Symfony HttpFoundation component, which provides the core abstractions for handling HTTP requests, responses, and sessions. It enables granular request matching, secure file upload management, and robust session storage with various backend handlers. The component also includes utilities for rate limiting and comprehensive testing constraints to validate HTTP behavior.
How it got here
2010–2012 — HttpFoundation security and session refactoring
20 changes.
This period focused on hardening the HttpFoundation component through stricter security validations, modernizing PHP type usage, and removing legacy session storage implementations. The work involved a comprehensive architectural overhaul of the Session component, introducing factory-based storage, specialized exceptions, and new features like auto-expiring flash messages. Extensive unit test coverage was added to ensure the reliability of these structural changes and new functionality.
2016–2023 — HttpFoundation component enhancements
11 changes.
This period focused on refining the HttpFoundation component by introducing granular request matchers and typed exceptions for better error handling and routing flexibility. Significant work was also dedicated to expanding test coverage, including new constraints for HTTP assertions and fixtures for session and rate limiter behaviors.
Features
Introduce peekable request rate limiting to reduce cache writes
The RateLimiter component now includes a \PeekableRequestRateLimiterInterface\ and an \AbstractRequestRateLimiter\ implementation, enabling consumers to check rate-limit status without immediately consuming a token. This allows scenarios like login throttling to 'peek' at the limit first and only consume a token on failure, significantly reducing write operations to the cache backend compared to the previous always-consume-then-reset approach.
RateLimiter · high confidence
New RequestMatcher components for granular request matching
The Symfony HttpFoundation component now includes a suite of dedicated request matcher classes (AttributesRequestMatcher, ExpressionRequestMatcher, HeaderRequestMatcher, HostRequestMatcher, IpsRequestMatcher, IsJsonRequestMatcher, MethodRequestMatcher, PathRequestMatcher, PortRequestMatcher, QueryParameterRequestMatcher, and SchemeRequestMatcher) that implement RequestMatcherInterface. These allow developers to match requests based on specific criteria such as attributes, expressions, headers, host, IP, JSON content, HTTP method, path, port, query parameters, and scheme, providing more modular and reusable routing logic.
RequestMatcher · high confidence
New Session component with usage tracking and factory support
The Session component now includes a new Session class that implements FlashBagAwareSessionInterface and supports usage reporting via a configurable usage reporter, allowing applications to detect and prevent unused session reads. A new SessionFactory and SessionFactoryInterface have been added to standardize session creation, while SessionBagProxy wraps session bags to track access for the usage reporter. The component also introduces SessionUtils for manipulating session cookies and defines core interfaces like SessionInterface and SessionBagInterface.
Session · high confidence
New session storage handlers and refactored base classes
This change introduces a new \AbstractSessionHandler\ base class that implements \SessionUpdateTimestampHandlerInterface\ to enable strict and lazy session handling, and a \ClearableSessionHandlerInterface\ for bulk session removal. It adds several new storage handlers: \MarshallingSessionHandler\ (wraps another handler with cache-style marshalling), \MigratingSessionHandler\ (reads from an old handler while writing to a new one for seamless migration), \NativeFileSessionHandler\ (a wrapper around PHP's native file handler with a \clear()\ method), \NullSessionHandler\ (for testing), \StrictSessionHandler\ (wraps legacy handlers to support timestamp updates), and \SessionHandlerFactory\ (a factory to instantiate handlers from DSN strings or connection objects). Existing handlers like \PdoSessionHandler\, \RedisSessionHandler\, \MemcachedSessionHandler\, and \MongoDbSessionHandler\ are updated to extend the new abstract base and implement the clearable interface.
Session/Storage/Handler · high confidence
Removals
Session storage classes removed from HttpFoundation namespace
The \NativeSessionStorage\, \PdoSessionStorage\, and \SessionStorageInterface\ classes have been deleted from the \Symfony\\Component\\HttpFoundation\\SessionStorage\ namespace. This change removes the legacy session storage implementations that were previously bundled with the HttpFoundation component, indicating a shift in how session handling is structured or provided within the framework.
SessionStorage · high confidence
Architecture
Refactored session storage into a factory-based architecture with a new MetadataBag
The Session/Storage component has been restructured to use a factory pattern for creating session storage instances, introducing \SessionStorageFactoryInterface\ and concrete factories for \NativeSessionStorage\, \PhpBridgeSessionStorage\, and \MockFileSessionStorage\. This change decouples storage creation from configuration, allowing for more flexible wiring in dependency injection containers. Additionally, the internal \MetaBag\ has been renamed to \MetadataBag\ to better reflect its role in tracking session creation, update, and lifetime metadata, and this bag is now consistently integrated into all storage implementations, including the mock storages used for testing.
Session/Storage · high confidence
Behavioural changes
HttpFoundation: Security hardening and behavioral refinements for requests, responses, and sessions
This update introduces several security and behavioral improvements across the HttpFoundation component. Security-wise, it enforces stricter validation for HTTP method overrides (blocking GET, HEAD, CONNECT, TRACE), rejects invalid cookie prefixes (\_\Secure-/, \\_Host-), and prevents magic byte injection in JSONP responses. Behaviorally, it changes the default httpOnly flag for cookies to match PHP's defaults, makes HTTP headers from proxies non-trusted by default, and deprecates legacy session options and compatibility layers for PHP \<5.4. Additionally, it adds support for the 308 Permanent Redirect, the CHIPS cookie attribute, and the Forwarded header, while fixing various parsing issues in Request and Response classes.
(repo-wide) · high confidence
Introduce session storage proxy classes with native PHP types
The Session/Storage/Proxy location now includes AbstractProxy and SessionHandlerProxy, which wrap the native PHP session handler to provide a consistent interface for session management. These classes introduce strict type hints for properties and methods, enforce that session ID and name cannot be changed once a session is active, and delegate all session operations (open, close, read, write, destroy, gc, create\_sid, validateId, updateTimestamp) to the underlying handler while marking session IDs as sensitive parameters.
Session/Storage/Proxy · high confidence
New typed exception classes for HTTP request handling
The HttpFoundation component introduces a dedicated namespace for request-related exceptions, replacing generic error handling with specific, typed classes. This includes \BadRequestException\ for malformed requests, \ConflictingHeadersException\ for header conflicts, \SuspiciousOperationException\ for security concerns, and \SessionNotFoundException\ for missing sessions. It also adds specific exceptions for signed URI validation (\ExpiredSignedUriException\, \UnsignedUriException\, \UnverifiedSignedUriException\) and JSON parsing (\JsonException\). These exceptions implement \RequestExceptionInterface\, signaling to applications that they should trigger an HTTP 400 response, and \SignedUriException\ classes are annotated with \WithHttpStatus\ to automatically map to 403 or 404 status codes.
Exception · high confidence
Refactored File and UploadedFile classes with safer move logic and Mime component integration
The File and UploadedFile classes in HttpFoundation have been refactored to improve safety and functionality. File now extends \\SplFileInfo and delegates mime-type and extension guessing to the optional Mime component, throwing a clear exception if the component is missing. The move() method on both File and UploadedFile now accepts an optional second argument to specify a new filename, and UploadedFile::move() specifically uses move\_uploaded\_file() for security when handling HTTP uploads. Additionally, a new Stream class was added to handle file streams of unknown size, and various error handling improvements were made, such as stripping HTML tags from error messages and using try/finally to restore error handlers.
File · high confidence
Refactored FlashBag implementations with modern PHP features and new AutoExpireFlashBag
The Session/Flash component has been rewritten to use modern PHP syntax, including constructor property promotion, native return types, and union types (e.g., \string\|array\). A new \AutoExpireFlashBag\ class has been introduced alongside the existing \FlashBag\, offering a distinct lifecycle where flash messages are automatically moved from a 'new' to a 'display' bucket between requests, ensuring they persist for one additional request before expiring. The \FlashBagInterface\ and both implementations now strictly enforce type hints for parameters and return values, and the \add\ method signature has been standardized to accept \mixed\ messages.
Session/Flash · high confidence
Session attributes moved to dedicated namespace with native type hints
The session attribute storage classes (\AttributeBag\ and \AttributeBagInterface\) have been moved to the \Symfony\\Component\\HttpFoundation\\Session\\Attribute\ namespace. This change introduces native PHP type declarations for properties and method signatures, replacing previous docblock-based typing, and implements \IteratorAggregate\ and \Countable\ interfaces to allow direct iteration and counting of session attributes.
Session/Attribute · high confidence
Split FileException into specialized upload and access exceptions
The single FileException class has been replaced by a hierarchy of specialized exceptions in the Symfony HttpFoundation File component. A base FileException now extends RuntimeException, while specific scenarios like access denial, file not found, and various PHP upload errors (form size, ini size, no file, partial upload, no temp dir, cannot write, extension) each have their own exception classes. This allows developers to catch specific upload failure modes rather than handling a generic exception.
File/Exception · high confidence
Test coverage
Added MongoDB client stub for isolated session storage handler tests; Added functional test fixtures for HTTP response behavior; Added session handler fixtures to verify SameSite cookie behavior; Added test fixtures for directory upload scenarios; Added test fixtures for session handler and enum mocking; Added tests for HttpFoundation request matchers; Added tests for HttpFoundation test constraints; Added tests for session storage handlers; Added unit tests for AbstractRequestRateLimiter behavior; Added unit tests for AttributeBag; Added unit tests for File and UploadedFile components; Added unit tests for FlashBag and AutoExpireFlashBag; Added unit tests for HttpFoundation components; Added unit tests for session storage components; Added unit tests for session storage proxy classes; Added unit tests for the Session component; New PHPUnit constraints for HTTP testing.
Dependencies
Symfony HttpFoundation requires PHP 8.4.1 and Symfony 7.4/8.0 components
The Symfony HttpFoundation component now mandates a minimum PHP version of 8.4.1 and requires Symfony components (Cache, Clock, DependencyInjection, ExpressionLanguage, HttpKernel, Mime, RateLimiter) at versions 7.4 or 8.0. Development dependencies have been updated to support Doctrine DBAL 4.3 and Predis 2.0, while the autoload configuration has been switched to PSR-4 with tests excluded from the classmap.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 45 → 58 (+12.2)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 91 → 91 (-0.4)
- Architecture 94 → 99 (+5.2)
- Maturity 49 → 47 (-1.3)
- Readiness 17 → 42 (+25.7)
- Security 100 → 100 (+0.0)
Resolved (25)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (10 lines × 2) (Request.php)
- Duplicated block (10 lines × 2) (Tests/AcceptHeaderTest.php)
- Duplicated block (11 lines × 2) (Request.php)
- Duplicated block (11 lines × 2) (Request.php)
- Duplicated block (11 lines × 2) (Request.php)
- Duplicated block (11 lines × 2) (Tests/IpUtilsTest.php)
- Duplicated block (29 lines × 2) (Tests/RequestTest.php)
- Duplicated block (5 lines × 2) (Tests/HeaderUtilsTest.php)
- Duplicated block (5 lines × 2) (Tests/Session/Attribute/AttributeBagTest.php)
- Duplicated block (5 lines × 2) (Tests/Session/Storage/Handler/PdoSessionHandlerTest.php)
- Duplicated block (6 lines × 2) (Session/Storage/Handler/PdoSessionHandler.php)
- Duplicated block (6 lines × 2) (Tests/RequestTest.php)
- Duplicated block (7 lines × 2) (Tests/AcceptHeaderTest.php)
- Duplicated block (7 lines × 2) (Tests/Session/Storage/Handler/AbstractRedisSessionHandlerTestCase.php)
- Duplicated block (8 lines × 2) (Tests/UrlHelperTest.php)
- Duplicated block (8 lines × 5) (Tests/Test/Constraint/ResponseHeaderLocationSameTest.php)
- Duplicated block (9 lines × 2) (Tests/CookieTest.php)
- Duplicated block (9 lines × 2) (Tests/ResponseTest.php)
- …and 5 more
New (94)
- BinaryFileResponse.prepare (cognitive 62) (BinaryFileResponse.php)
- BinaryFileResponse.prepare (cyclomatic 29) (BinaryFileResponse.php)
- BinaryFileResponse.sendContent (cognitive 24) (BinaryFileResponse.php)
- BinaryFileResponse.sendContent (cyclomatic 17) (BinaryFileResponse.php)
- Change coupling: HeaderBag.php ↔ AttributeBag.php (HeaderBag.php)
- ClassTooLong: PdoSessionHandler (Session/Storage/Handler/PdoSessionHandler.php)
- ClassTooLong: Request (Request.php)
- ClassTooLong: Response (Response.php)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (File/File.php)
- Duplicated block (10 lines × 2) (Request.php)
- Duplicated block (11 lines × 2) (Response.php)
- Duplicated block (13 lines × 2) (InputBag.php)
- Duplicated block (4–26 lines × 3) (Session/Storage/Handler/PdoSessionHandler.php)
- Duplicated block (5 lines × 2) (File/File.php)
- Duplicated block (5 lines × 2) (Session/Storage/Handler/PdoSessionHandler.php)
- Duplicated block (5 lines × 3) (Session/Storage/Handler/PdoSessionHandler.php)
- …and 74 more
Changes since last survey
- 119 commits — 107 feature/other, 12 fixes
By area
- (repo) — 76 commits
- (root) — 24 commits
- Tests/Session — 7 commits
- Session/Storage — 5 commits
- RequestMatcher/PathRequestMatcher.php — 1 commit
- RequestMatcher/QueryParameterRequestMatcher.php — 1 commit
- Session/Attribute — 1 commit
- Tests/Fixtures — 1 commit
- Tests/IpUtilsTest.php — 1 commit
- Tests/RequestTest.php — 1 commit
- Tests/ServerBagTest.php — 1 commit
Notable commits
- fix: PHP CS Fixer: fix minor detected issues
- fix: Revert "Give the Redis test probes an explicit connect timeout"
- fix: [HttpFoundation] Fix IpUtils::anonymize() for non-canonical IPv4-mapped addresses
- fix: [HttpFoundation] Fix hitting the PCRE size limit with many trusted host patterns
- fix: [HttpFoundation] Fix parsing hosts and schemes in URLs
- fix: [HttpFoundation] Fix port stripping on IPv4-mapped IPv6 forwarded addresses
- fix: [HttpFoundation] Fix: Encode path in X-Accel-Redirect header
- fix: bug #65683 [HttpFoundation] Allow-list the values of the "X-Sendfile-Type" header (nicolas-grekas)
- fix: bug #65729 [HttpFoundation] Reject reserved characters in the cookie path and domain (nicolas-grekas)
- fix: bug #65743 [HttpFoundation] Encode the path in the X-Accel-Redirect header (Athorcis)
- fix: bug #65775 [HttpFoundation] Match paths with the DOTALL modifier (nicolas-grekas)
- fix: bug #66151 [HttpFoundation] Expose header and attribute keys as strings (nicolas-grekas)
- change: Check arrays and bools directly instead of comparing them to count()/true/false/[]
- change: Check arrays and bools directly instead of comparing them to count()/true/false/[]
- change: Convert the merged-up session id test to a DataProvider attribute
- change: Give the Redis test probes an explicit connect timeout
- change: Merge branch '5.4' into 6.4
- change: Merge branch '5.4' into 6.4
- change: Merge branch '5.4' into 6.4
- change: Merge branch '5.4' into 6.4
- …and 99 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
symfony/http-foundation was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1c588354b1d2c94ed588edc33914bbf2978cd3ce — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.