17/01
2018
Wallogit.com
2017 © Pedro Peláez
CSRF protection - PHP security classes to avoid vulnerabilities
CSRF protection - PHP security classes to avoid vulnerabilities, (*1)
composer require hadi/csrf
Add CSRF token to form, (*2)
Then check CSRF token in your form submission area -, (*3)
session_start();
require_once __DIR__ . '/PATH_TO_YOUR_AUTOLOAD/vendor/autoload.php';
$csrf = new \Hadi\Csrf();
if(isset($_POST['submit'])) {
if($csrf->validRequest()) {
// Valid request
}
else {
// invalid request
}
}
$csrf->reset(); // or $csrf->deleteToken();
Have fun!, (*4)