dkplus/csrf-api-unprotection-bundle
Composer 安装命令:
composer require dkplus/csrf-api-unprotection-bundle
包简介
Disables the CSRF-token validation for all urls that matches a given expression.
README 文档
README
When developing stateless REST-APIs you do not want to CSRF token validation. Fortunately FOSRest provides the ability to disable it.
The solution does not work if you do not have a ROLE for all API users.
This Bundle disables the CSRF token validation based upon the URL of the request.
So if your API has a global prefix like /api/ you can disable the CSRF token validation for all your API forms.
Installation
Step 1: Download the Bundle
Installation of this Bundle uses composer. It requires you to have Composer installed globally. For composer documentation, please refer to getcomposer.org.
Open a command console, enter your project directory and execute the following command to download the latest stable version of this bundle:
composer require dkplus/csrf-api-unprotection-bundle
Step 2: Enable the Bundle within your AppKernel
Then, enable the bundle by adding the following line in the app/AppKernel.php file of your project:
<?php class AppKernel extends Kernel { public function registerBundles() { $bundles = array( // … new Dkplus\CsrfApiUnprotectionBundle\DkplusCsrfApiUnprotectionBundle, ); // … } // … }
That's everything you need :-)
Configuration
The default configuration disables the CSRF token validation for all uris
that begins with /api/ regardless which environment you are using.
dkplus_csrf_api_unprotection: rules: match_uri: - "#^(/app(_[a-zA-Z]*)?.php)?/api/#"
dkplus/csrf-api-unprotection-bundle 适用场景与选型建议
dkplus/csrf-api-unprotection-bundle 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 5.39k 次下载、GitHub Stars 达 0, 最近一次更新时间为 2015 年 06 月 28 日, 在 PHP 生态内属于活跃度较高的组件。
我们在过去多个企业项目中使用过 dkplus/csrf-api-unprotection-bundle 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 dkplus/csrf-api-unprotection-bundle 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
统计信息
- 总下载量: 5.39k
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 1
- 点击次数: 27
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2015-06-28