17/01
2018
CSRF protection - PHP security classes to avoid vulnerabilities
CSRF protection - PHP security classes to avoid vulnerabilities, (*1)
composer require hadi/csrf
Add CSRF token to form, (*2)
Then check CSRF token in your form submission area -, (*3)
session_start(); require_once __DIR__ . '/PATH_TO_YOUR_AUTOLOAD/vendor/autoload.php'; $csrf = new \Hadi\Csrf(); if(isset($_POST['submit'])) { if($csrf->validRequest()) { // Valid request } else { // invalid request } } $csrf->reset(); // or $csrf->deleteToken();
Have fun!, (*4)