schnittstabil / csrf-tokenservice
无状态CSRF(跨站请求伪造)令牌服务。
3.1.0
2017-09-05 18:57 UTC
Requires
- php: >=5.6.0
- spomky-labs/base64url: ^1.0
Requires (Dev)
README
无状态CSRF(跨站请求伪造)令牌服务 🍖
安装
$ composer require schnittstabil/csrf-tokenservice
用法
<?php require __DIR__.'/vendor/autoload.php'; use Schnittstabil\Csrf\TokenService\TokenService; // Shared secret key used for generating and validating token signatures: $key = 'This key is not so secret - change it!'; // Time to Live in seconds; default is 1440 seconds === 24 minutes: $ttl = 1440; // create the TokenService $tokenService = new TokenService($key, $ttl); // generate a URL-safe token, using the name of the authenticated user as nonce: $token = $tokenService->generate($_SERVER['PHP_AUTH_USER']); // validate the token - stateless; no session needed if (!$tokenService->validate($_SERVER['PHP_AUTH_USER'], $token)) { http_response_code(403); echo '<h2>403 Access Forbidden, bad CSRF token</h2>'; exit(); }
相关
- schnittstabil/psr7-csrf-middleware – (无状态的) PSR-7 CSRF 保护中间件
- schnittstabil/csrf-twig-helpers – 用于令牌渲染的Twig助手
许可协议
MIT © Michael Mayer