In security.yml
I have defined below:
access_control:
- { path: ^/login, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/api/getDays, roles: IS_AUTHENTICATED_ANONYMOUSLY }
# - { path: ^/admin, roles: ROLE_ADMIN }
- { path: ^/, roles: ROLE_USER }
- { path: ^/api, roles: PUBLIC_ACCESS }
But http://localhost:8000/api/search.json
always redirects to login page
Once a route matches the pattern, the system halts the process and does not proceed further. So, your
access_control
applies the third line. Switch line 3 and 4, and it should work:Source: How Does the Security access_control Work?