/symfony-voters
Implement granular authorization with Symfony Voters; decouple permission logic from controllers; test authorization separately
$ npx -y skills add dev-toolings/superpowers-symfony --skill symfony-voters --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/symfony-voters
Context preview
The summary Claude sees to decide when to auto-load this skill.
Implement granular authorization with Symfony Voters; decouple permission logic from controllers; test authorization separately
SKILL.md
symfony-voters.SKILL.mdname: symfony:symfony-voters allowed-tools: - Read - Write - Edit - Bash - Glob - Grep description: Implement granular authorization with Symfony Voters; decouple permission logic from controllers; test authorization separately
Symfony Voters (Symfony)
Use when
- Hardening access-control or validation boundaries.
- Aligning voters/security expressions with domain rules.
Default workflow
1. Map actor/resource/action decision matrix. 2. Implement voter/constraint logic at the right boundary. 3. Wire checks at controllers and API operations. 4. Test allowed/forbidden/invalid paths comprehensively.
Guardrails
- Avoid policy logic duplication across layers.
- Do not leak privileged state via error detail.
- Preserve explicit deny behavior for sensitive actions.
Progressive disclosure
- Use this file for execution posture and risk controls.
- Open references when deep implementation details are needed.
Output contract
- Security boundary updates.
- Integration points enforcing decisions.
- Negative-path test results.
References
- `reference.md`
- `docs/complexity-tiers.md`
Symfony AI development superpowers for Claude Code. 44 expert skills, 7 specialized subagents, and 13 slash commands covering API Platform v4, Doctrine ORM 3, TDD with Pest & PHPUnit, Symfony Messenger, security/voters, and DDD / hexagonal architecture.
Repo: dev-toolings/superpowers-symfony
Other skills on dev-toolings-superpowers-symfony.
- /api-platform-dto-resources
Map entities to API DTOs in API Platform v4 with the Symfony Object Mapper (#[Map], stateOptions) for decoupled input/output contracts
Open skill - /api-platform-filters
Implement API Platform filters - v4 Parameters API (QueryParameter) and legacy #[ApiFilter] - for search, date, range, boolean, and custom filtering
Open skill - /api-platform-resources
Configure API Platform v4 resources with explicit operations, pagination, and typed OpenAPI for clean, versioned REST/GraphQL APIs
Open skill - /api-platform-security
Secure API Platform resources with security expressions, voters, securityPostValidation, and operation-level access control
Open skill - /api-platform-serialization
Control API Platform serialization with groups, #[Context], IRI links (readableLink/writableLink), and custom context builders
Open skill - /api-platform-state-providers
Master API Platform v4 State Providers and Processors (ProviderInterface/ProcessorInterface) to decouple data retrieval and persistence from entities
Open skill

