定制 fyre/csrf 二次开发

按需修改功能、优化性能、对接业务系统,提供一站式技术支持

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

fyre/csrf

Composer 安装命令:

composer require fyre/csrf

包简介

A CSRF protetion library.

README 文档

README

FyreCSRF is a free, open-source CSRF protection library for PHP.

Table Of Contents

Installation

Using Composer

composer require fyre/csrf

In PHP:

use Fyre\Security\CsrfProtection;

Basic Usage

$csrfProtection = new CsrfProtection($container, $config);

Default configuration options will be resolved from the "Csrf" key in the Config.

  • $options is an array containing the configuration options.
    • cookie is an array containing CSRF cookie options.
      • name is a string representing the cookie name, and will default to "CsrfToken".
      • expires is a number representing the cookie lifetime, and will default to 0.
      • domain is a string representing the cookie domain, and will default to "".
      • path is a string representing the cookie path, and will default to "/".
      • secure is a boolean indicating whether to set a secure cookie, and will default to true.
      • httpOnly is a boolean indicating whether to the cookie should be HTTP only, and will default to false.
      • sameSite is a string representing the cookie same site, and will default to "Lax".
    • salt is a string representing the CSRF session key and will default to "_csrfToken".
    • field is a string representing the CSRF token field name, and will default to "csrf_token".
    • header is a string representing the CSRF token header name, and will default to "Csrf-Token".
    • skipCheck is a Closure that accepts a ServerRequest as the first argument.
$container->use(Config::class)->set('Csrf', $options);

Autoloading

It is recommended to bind the CsrfProtection to the Container as a singleton.

$container->singleton(CsrfProtection::class);

Any dependencies will be injected automatically when loading from the Container.

$csrfProtection = $container->use(CsrfProtection::class);

Methods

Before Response

Update the ClientResponse before sending to client.

$response = $csrfProtection->beforeResponse($request, $response);

Check Token

Check CSRF token.

$csrfProtection->checkToken($request);

Get Cookie Token

Get the CSRF cookie token.

$cookieToken = $csrfProtection->getCookieToken();

Get Field

Get the CSRF token field name.

$field = $csrfProtection->getField();

Get Form Token

Get the CSRF form token.

$formToken = $csrfProtection->getFormToken();

Get Header

Get the CSRF token header name.

$header = $csrfProtection->getHeader();

Middleware

use Fyre\Security\Middleware\CsrfProtectionMiddleware;
  • $csrfProtection is a CsrfProtection.
$middleware = new CsrfProtectionMiddleware($csrfProtection);

Any dependencies will be injected automatically when loading from the Container.

$middleware = $container->build(CsrfProtectionMiddleware::class);

Handle

Handle a ServerRequest.

$response = $middleware->handle($request, $next);

This method will return a ClientResponse.

fyre/csrf 适用场景与选型建议

fyre/csrf 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 140 次下载、GitHub Stars 达 0, 最近一次更新时间为 2022 年 04 月 03 日, 在 PHP 生态内属于活跃度较高的组件。

我们在过去多个企业项目中使用过 fyre/csrf 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。

围绕 fyre/csrf 我们能提供哪些服务?
定制开发 / 二次开发

基于 fyre/csrf 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。

BUG 修复 & 性能优化

线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。

项目外包 & 长期维护

承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。

yvsm@zunyunkeji.com QQ:316430983 微信:yvsm316 西安尊云信息科技 · 专注 PHP / Go / 分布式系统研发

统计信息

  • 总下载量: 140
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 0
  • 点击次数: 3
  • 依赖项目数: 3
  • 推荐数: 0

GitHub 信息

  • Stars: 0
  • Watchers: 1
  • Forks: 1
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2022-04-03