<!-- Parent: ../AGENTS.md -->
<!-- Generated: 2026-07-02 | Updated: 2026-07-02 -->

# packages

## Purpose
Per-bundle configuration YAML. One file per bundle/concern, applied by environment.

## Key Files
| File | Description |
|------|-------------|
| `framework.yaml` | Core framework: session, CSRF, http-method-override. **Session lifetime comment says "2 minutes" but the actual values are 2–3 days (mismatch — verify before relying on the comment)** |
| `security.yaml` | **Firewall uses an in-memory user provider; there is no DB-backed authentication at the firewall level.** Real admin/client auth is custom session logic in controllers. Access control here is minimal |
| `doctrine.yaml` | DB connection + ORM mapping (driver, entity paths) |
| `doctrine_migrations.yaml` | Migrations path/namespace |
| `twig.yaml` | Twig paths, form theme, global vars |
| `mailer.yaml` | Mailer transport (**DSN/credentials come from `.env`, which has committed SMTP creds — security issue**) |
| `messenger.yaml` | Messenger transports/routing |
| `monolog.yaml` | Logging channels/handlers per env |
| `notifier.yaml` | Symfony Notifier config |
| `asset_mapper.yaml` | AssetMapper paths |
| `cache.yaml`, `csrf.yaml`, `routing.yaml`, `translation.yaml`, `validator.yaml`, `debug.yaml`, `web_profiler.yaml` | Respective bundle configs |

## For AI Agents

### Working In This Directory
- Env-specific overrides use the `when@dev` / `when@test` / `when@prod` YAML keys.
- Run `php bin/console cache:clear` after edits.
- **Do not treat `security.yaml` as the source of auth truth** — see root `AGENTS.md`. If you intend to move to real firewall auth, that is a significant refactor (custom session checks are spread across controllers).
- Two real issues to fix here eventually: session lifetime (comment vs. values), and mailer credentials sourced from a committed `.env`.

## Dependencies

### External
- All bundles registered in `config/bundles.php`.

<!-- MANUAL: -->
