fyre/csrf
Composer 安装命令:
composer require fyre/csrf
包简介
A CSRF protetion library.
README 文档
README
FyreCSRF is a free, open-source CSRF protection library for PHP.
Table Of Contents
Installation
Using Composer
composer require fyre/csrf
In PHP:
use Fyre\Security\CsrfProtection;
Basic Usage
$csrfProtection = new CsrfProtection($container, $config);
Default configuration options will be resolved from the "Csrf" key in the Config.
$optionsis an array containing the configuration options.cookieis an array containing CSRF cookie options.nameis a string representing the cookie name, and will default to "CsrfToken".expiresis a number representing the cookie lifetime, and will default to 0.domainis a string representing the cookie domain, and will default to "".pathis a string representing the cookie path, and will default to "/".secureis a boolean indicating whether to set a secure cookie, and will default to true.httpOnlyis a boolean indicating whether to the cookie should be HTTP only, and will default to false.sameSiteis a string representing the cookie same site, and will default to "Lax".
saltis a string representing the CSRF session key and will default to "_csrfToken".fieldis a string representing the CSRF token field name, and will default to "csrf_token".headeris a string representing the CSRF token header name, and will default to "Csrf-Token".skipCheckis a Closure that accepts a ServerRequest as the first argument.
$container->use(Config::class)->set('Csrf', $options);
Autoloading
It is recommended to bind the CsrfProtection to the Container as a singleton.
$container->singleton(CsrfProtection::class);
Any dependencies will be injected automatically when loading from the Container.
$csrfProtection = $container->use(CsrfProtection::class);
Methods
Before Response
Update the ClientResponse before sending to client.
$response = $csrfProtection->beforeResponse($request, $response);
Check Token
Check CSRF token.
$requestis the ServerRequest.
$csrfProtection->checkToken($request);
Get Cookie Token
Get the CSRF cookie token.
$cookieToken = $csrfProtection->getCookieToken();
Get Field
Get the CSRF token field name.
$field = $csrfProtection->getField();
Get Form Token
Get the CSRF form token.
$formToken = $csrfProtection->getFormToken();
Get Header
Get the CSRF token header name.
$header = $csrfProtection->getHeader();
Middleware
use Fyre\Security\Middleware\CsrfProtectionMiddleware;
$csrfProtectionis a CsrfProtection.
$middleware = new CsrfProtectionMiddleware($csrfProtection);
Any dependencies will be injected automatically when loading from the Container.
$middleware = $container->build(CsrfProtectionMiddleware::class);
Handle
Handle a ServerRequest.
$requestis a ServerRequest.$nextis a Closure.
$response = $middleware->handle($request, $next);
This method will return a ClientResponse.
fyre/csrf 适用场景与选型建议
fyre/csrf 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 140 次下载、GitHub Stars 达 0, 最近一次更新时间为 2022 年 04 月 03 日, 在 PHP 生态内属于活跃度较高的组件。
我们在过去多个企业项目中使用过 fyre/csrf 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 fyre/csrf 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
统计信息
- 总下载量: 140
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 3
- 依赖项目数: 3
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2022-04-03