GET https://www.25dagen.be/admin/login/csrf-token

LoginController :: csrfTokenAction

Request

GET Parameters

None

POST Parameters

None

Uploaded Files

None

Request Attributes

Key Value
_controller
"Pimcore\Bundle\AdminBundle\Controller\Admin\LoginController::csrfTokenAction"
_event_controller
Pimcore\Bundle\AdminBundle\Controller\Admin\LoginController {#371
  #container: Symfony\Component\DependencyInjection\Argument\ServiceLocator {#1531 …}
  #tokenResolver: Pimcore\Security\User\TokenStorageUserResolver {#607 …}
  #pimcoreSerializer: Pimcore\Serializer\Serializer {#1532 …}
  #responseHelper: Pimcore\Http\ResponseHelper {#574 …}
  #translator: Pimcore\Translation\Translator {#411 …}
  #bundleManager: Pimcore\Extension\Bundle\PimcoreBundleManager {#508 …}
  #eventDispatcher: Symfony\Component\EventDispatcher\EventDispatcher {#100 …}
}
_firewall_context
"security.firewall.map.context.pimcore_admin"
_pimcore_context
"admin"
_route
"pimcore_admin_login_csrf_token"
_route_params
[]
_security_authenticators
[]
_security_firewall_run
"_security_pimcore_admin"
_security_skipped_authenticators
[
  Pimcore\Bundle\AdminBundle\Security\Authenticator\AdminTokenAuthenticator {#1501
    #twoFactorRequired: false
    #dispatcher: Symfony\Component\EventDispatcher\EventDispatcher {#100 …}
    #router: Symfony\Cmf\Component\Routing\ChainRouter {#489 …}
    #translator: Pimcore\Translation\Translator {#411 …}
    #logger: Monolog\Logger {#1419 …}
  }
  Scheb\TwoFactorBundle\Security\Http\Authenticator\TwoFactorAuthenticator {#1504
    -logger: Monolog\Logger {#1419 …}
    -twoFactorFirewallConfig: Scheb\TwoFactorBundle\Security\TwoFactor\TwoFactorFirewallConfig {#1502 …}
    -tokenStorage: Symfony\Component\Security\Core\Authentication\Token\Storage\UsageTrackingTokenStorage {#608 …}
    -successHandler: Scheb\TwoFactorBundle\Security\Http\Authentication\DefaultAuthenticationSuccessHandler {#1505 …}
    -failureHandler: Scheb\TwoFactorBundle\Security\Http\Authentication\DefaultAuthenticationFailureHandler {#1506 …}
    -authenticationRequiredHandler: Scheb\TwoFactorBundle\Security\Http\Authentication\DefaultAuthenticationRequiredHandler {#1507 …}
    -eventDispatcher: Symfony\Component\EventDispatcher\EventDispatcher {#100 …}
  }
  Symfony\Component\Security\Http\Authenticator\FormLoginAuthenticator {#1446
    -options: [
      "username_parameter" => "username"
      "password_parameter" => "password"
      "check_path" => "pimcore_admin_login_check"
      "post_only" => true
      "form_only" => false
      "enable_csrf" => false
      "csrf_parameter" => "_csrf_token"
      "csrf_token_id" => "authenticate"
      "login_path" => "pimcore_admin_login"
      "use_forward" => false
    ]
    -httpKernel: ? Symfony\Component\HttpKernel\HttpKernelInterface
    -httpUtils: Symfony\Component\Security\Http\HttpUtils {#1443 …}
    -userProvider: Pimcore\Security\User\UserProvider {#1447 …}
    -successHandler: Symfony\Component\Security\Http\Authentication\DefaultAuthenticationSuccessHandler {#1444 …}
    -failureHandler: Symfony\Component\Security\Http\Authentication\DefaultAuthenticationFailureHandler {#1445 …}
  }
]

Request Headers

Header Value
accept
"*/*"
accept-encoding
"gzip, deflate, br, zstd"
accept-language
"fr-FR,fr;q=0.9,en-US;q=0.8,en;q=0.7"
cookie
"pimcore_admin_auth_profile_token=52573f; _ga=GA1.1.317571085.1767973143; _ga_5RK8569WM7=GS2.1.s1767973142$o1$g1$t1767973405$j60$l0$h0; B2B_SESSION_ID=10tdt9h13b3sehac7apfr1khbe"
front-end-https
"on"
host
"www.25dagen.be"
priority
"u=1, i"
referer
"https://www.25dagen.be/admin/login?session_expired=true"
sec-ch-ua
""Google Chrome";v="143", "Chromium";v="143", "Not A(Brand";v="24""
sec-ch-ua-mobile
"?0"
sec-ch-ua-platform
""macOS""
sec-fetch-dest
"empty"
sec-fetch-mode
"cors"
sec-fetch-site
"same-origin"
user-agent
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
x-forwarded-for
"149.154.213.49"
x-forwarded-proto
"https"
x-php-ob-level
"1"
x-real-ip
"149.154.213.49"

Request Content

Request content not available (it was retrieved as a resource).

Response

Response Headers

Header Value
cache-control
"max-age=0, max-stale=0, must-revalidate, no-cache, no-store, no-transform, post-check=0, pre-check=0, private"
content-language
"en"
content-security-policy
"default-src 'self' 'self';img-src * data: blob: ;media-src 'self' data: ;script-src 'self' 'nonce-kA7EBccaAqXhzHS9m5YQUz40b1wzxge8' 'unsafe-eval' https://buttons.github.io/buttons.js https://code.jquery.com/ 'self' 'unsafe-inline' 'unsafe-eval' https://buttons.github.io https://cdnjs.cloudflare.com https://cdn.datatables.net https://ajax.googleapis.com;style-src 'self' 'unsafe-inline' 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.datatables.net https://use.typekit.net https://p.typekit.net https://fonts.googleapis.com https://cdn.quilljs.com;frame-src 'self' data: https://www.youtube-nocookie.com/ https://www.dailymotion.com/ https://player.vimeo.com/;frame-ancestors 'self' ;connect-src 'self' blob: https://license.pimcore.com/ https://nominatim.openstreetmap.org/;font-src 'self' 'self' https://fonts.gstatic.com https://use.typekit.net;worker-src 'self' blob: "
content-type
"application/json"
date
"Sun, 11 Jan 2026 20:24:54 GMT"
expires
"Tue, 01 Jan 1980 00:00:00 GMT"
pragma
"no-cache"
x-debug-token
"158504"
x-frame-options
"deny"
x-powered-by
"pimcore"

Cookies

Request Cookies

Key Value
B2B_SESSION_ID
"10tdt9h13b3sehac7apfr1khbe"
_ga
"GA1.1.317571085.1767973143"
_ga_5RK8569WM7
"GS2.1.s1767973142$o1$g1$t1767973405$j60$l0$h0"
pimcore_admin_auth_profile_token
"52573f"

Response Cookies

No response cookies

Session

Session Metadata

Key Value
Created
"Sun, 11 Jan 26 16:48:54 +0100"
Last used
"Sun, 11 Jan 26 21:01:55 +0100"
Lifetime
86400

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
APP_DEBUG
"0"
APP_ENV
"dev"
MAILER_DSN
"brevo+smtp://9f8550001%40smtp-brevo.com:xsmtpsib-d009afc74f337ec0f53d5ea6ef13ef13f9a7a0190ceb7c3c8a83818199589b62-rivYgAO6ytvIBSNC@default"
PIMCORE_DEV_MODE
"false"

Defined as regular env variables

Key Value
APP_PROJECT_DIR
"/var/www/www.25jours.be/www"
APP_RUNTIME
"Symfony\Component\Runtime\SymfonyRuntime"
APP_RUNTIME_OPTIONS
[
  "project_dir" => "/var/www/www.25jours.be/www"
]
CONTEXT_DOCUMENT_ROOT
"/var/www/www.25jours.be/www/public"
CONTEXT_PREFIX
""
DOCUMENT_ROOT
"/var/www/www.25jours.be/www/public"
FCGI_ROLE
"RESPONDER"
GATEWAY_INTERFACE
"CGI/1.1"
HOME
"/var/www/www.25jours.be/"
HTTPS
"on"
HTTP_ACCEPT
"*/*"
HTTP_ACCEPT_ENCODING
"gzip, deflate, br, zstd"
HTTP_ACCEPT_LANGUAGE
"fr-FR,fr;q=0.9,en-US;q=0.8,en;q=0.7"
HTTP_COOKIE
"pimcore_admin_auth_profile_token=52573f; _ga=GA1.1.317571085.1767973143; _ga_5RK8569WM7=GS2.1.s1767973142$o1$g1$t1767973405$j60$l0$h0; B2B_SESSION_ID=10tdt9h13b3sehac7apfr1khbe"
HTTP_FRONT_END_HTTPS
"on"
HTTP_HOST
"www.25dagen.be"
HTTP_PRIORITY
"u=1, i"
HTTP_REFERER
"https://www.25dagen.be/admin/login?session_expired=true"
HTTP_SEC_CH_UA
""Google Chrome";v="143", "Chromium";v="143", "Not A(Brand";v="24""
HTTP_SEC_CH_UA_MOBILE
"?0"
HTTP_SEC_CH_UA_PLATFORM
""macOS""
HTTP_SEC_FETCH_DEST
"empty"
HTTP_SEC_FETCH_MODE
"cors"
HTTP_SEC_FETCH_SITE
"same-origin"
HTTP_USER_AGENT
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
HTTP_X_FORWARDED_FOR
"149.154.213.49"
HTTP_X_FORWARDED_PROTO
"https"
HTTP_X_REAL_IP
"149.154.213.49"
PATH
"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin"
PHP_SELF
"/index.php"
QUERY_STRING
""
REDIRECT_HTTPS
"on"
REDIRECT_STATIC_PAGE_URI
"/%home"
REDIRECT_STATUS
"200"
REDIRECT_URL
"/admin/login/csrf-token"
REMOTE_ADDR
"127.0.0.1"
REMOTE_PORT
"35458"
REQUEST_METHOD
"GET"
REQUEST_SCHEME
"http"
REQUEST_TIME
1768163094
REQUEST_TIME_FLOAT
1768163094.9131
REQUEST_URI
"/admin/login/csrf-token"
SCRIPT_FILENAME
"/var/www/www.25jours.be/www/public/index.php"
SCRIPT_NAME
"/index.php"
SERVER_ADDR
"127.0.0.1"
SERVER_ADMIN
"support@cblue.be"
SERVER_NAME
"www.25dagen.be"
SERVER_PORT
"80"
SERVER_PROTOCOL
"HTTP/1.1"
SERVER_SIGNATURE
""
SERVER_SOFTWARE
"Apache"
STATIC_PAGE_URI
"/%home"
SYMFONY_DOTENV_PATH
"/var/www/www.25jours.be/www/.env"
SYMFONY_DOTENV_VARS
"APP_ENV,APP_DEBUG,PIMCORE_DEV_MODE,MAILER_DSN"
USER
"25jours"
proxy-nokeepalive
"1"