# Segurança avançada (Symfony) > Custom authenticators, voters, security expressions, proteção CSRF, prevenção de XSS, rate limiting, hardening em produção, configurações incorretas de JWT/OAuth2 - 22 perguntas de entrevista - Senior - [Perguntas de entrevista: Symfony](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista.md) ## 1. Qual interface um custom authenticator deve implementar no Symfony 6+? **Resposta** No Symfony 6+, os custom authenticators devem implementar AuthenticatorInterface do componente Security HTTP. Essa interface define os métodos supports(), authenticate(), onAuthenticationSuccess(), onAuthenticationFailure() e, opcionalmente, createToken(). Ela substitui o antigo sistema Guard que era usado no Symfony 4/5. ## 2. Qual é o papel do método supports() em um custom authenticator? **Resposta** O método supports() determina se o authenticator deve processar a requisição atual. Ele recebe a Request e retorna um booleano. Se for true, o método authenticate() seguido de onAuthenticationSuccess() ou onAuthenticationFailure() será chamado. Isso permite ter vários authenticators ativos no mesmo firewall, cada um lidando com um tipo de autenticação específico. ## 3. O que o método authenticate() de um custom authenticator deve retornar em caso de sucesso? **Resposta** O método authenticate() deve retornar um objeto Passport contendo um UserBadge (identificador do usuário) e credentials badges. O Passport também pode conter badges adicionais como CsrfTokenBadge ou RememberMeBadge. O Symfony usa então esse Passport para criar o token de autenticação e carregar o usuário através do UserProvider. ## Mais 19 perguntas disponiveis - Como definir um Voter personalizado para controlar o acesso a um recurso específico? - Qual estratégia do AccessDecisionManager é recomendada para aplicações que exigem segurança rigorosa? Cadastre-se gratis: https://sharpskill.dev/pt/login ## Outros temas de entrevista Symfony - [PHP Moderno (8.1+)](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/php-modern-features.md): 20 perguntas, Junior - [Fundamentos do Symfony](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/symfony-basics.md): 25 perguntas, Junior - [Routing & Controllers](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/routing-controllers.md): 20 perguntas, Junior - [Twig & Templates](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/twig-templates.md): 20 perguntas, Junior - [Fundamentos do Doctrine ORM](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/doctrine-orm-basics.md): 25 perguntas, Junior - [Formulários Symfony](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/forms.md): 22 perguntas, Junior - [Validação de dados](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/validation.md): 18 perguntas, Junior - [Dependency Injection & Services](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/dependency-injection.md): 24 perguntas, Mid-Level - [Security & Authentication](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/security-authentication.md): 26 perguntas, Mid-Level - [Doctrine avançado](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/doctrine-advanced.md): 24 perguntas, Mid-Level - [API Platform](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/api-platform.md): 22 perguntas, Mid-Level - [Serializer Component](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/serializer.md): 20 perguntas, Mid-Level - [Events & Event Subscribers](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/events-subscribers.md): 20 perguntas, Mid-Level - [Console & Commands](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/console-commands.md): 18 perguntas, Mid-Level - [Messenger Component](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/messenger.md): 22 perguntas, Mid-Level - [HTTP Client](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/http-client.md): 18 perguntas, Mid-Level - [Cache e Desempenho](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/cache.md): 20 perguntas, Mid-Level - [Workflow Component](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/workflow.md): 18 perguntas, Mid-Level - [Testing Symfony](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/testing.md): 22 perguntas, Mid-Level - [Mailer Component](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/mailer.md): 16 perguntas, Mid-Level - [Traduções e i18n](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/translations.md): 16 perguntas, Mid-Level - [EasyAdmin Bundle](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/easyadmin.md): 18 perguntas, Mid-Level - [Arquitetura Symfony](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/architecture-patterns.md): 24 perguntas, Senior - [Desempenho e otimização](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/performance-optimization.md): 22 perguntas, Senior - [Bundles Personalizados](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/custom-bundles.md): 20 perguntas, Senior - [Microservices com Symfony](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/microservices.md): 22 perguntas, Senior - [Real-time & WebSockets](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/real-time.md): 18 perguntas, Senior - [Deployment & DevOps](https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/deployment-devops.md): 20 perguntas, Senior --- Source: SharpSkill (https://sharpskill.dev), tech interview preparation for your real stack. HTML version of this page: https://sharpskill.dev/pt/technologies/symfony/perguntas-entrevista/security-advanced