shadowprince/forman-csrf
Composer 安装命令:
composer require shadowprince/forman-csrf
包简介
CSRF protection plugin for shadowprince/forman
README 文档
README
Forman-Recaptcha - plugin for forman, adding automatic CSRF-protection for all forms. Plugin works at background, no code needed.
Mechanism
- Generates and stores token at every form
process - Compares token from form data and user cookies, if cookie not exist or not matches - field error will be added and
verify(soprocesstoo) fails - Removes
csrf_tokenfromprocessresult, so you'll not even notice
You can turn it off for one form
\Forman\CSRFPlugin::disable(); if ($data = $form->process($_POST)) { // now there is no CSRF } \Forman\CSRFPlugin::enable();
Or global
// somewhere in bootstrap \Forman\CSRFPlugin::disableGlobal(); // so any enable() will not work now
统计信息
- 总下载量: 4
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 0
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: BSD
- 更新时间: 2013-10-24