getRequestUri(), '/api/')) { return false; } // API documentation is only available to registered and logged-in users if (str_starts_with($request->getRequestUri(), '/api/doc')) { return false; } // let's use this firewall if a Bearer token is set in the header // other cases like "bearer" are rejected earlier if (($auth = $request->headers->get('Authorization')) !== null && str_starts_with($auth, 'Bearer ')) { return true; } // checking for a previous session allows us to skip the API firewall and token access handler // we simply re-use the existing session when doing API calls from the frontend. // it is not necessary to check headers. if there is no valid session, we should always use this firewall return !$request->hasPreviousSession(); } }