mirror of
https://github.com/billz/raspap-webgui.git
synced 2025-03-01 10:31:47 +00:00
send CSRF token in a response header,
update the page's CSRF tokens with the new token from the response header, verify csrf token in ajax endpoints, initialize a session for every endpoint
This commit is contained in:
11
includes/csrf.php
Normal file
11
includes/csrf.php
Normal file
@@ -0,0 +1,11 @@
|
||||
<?php
|
||||
|
||||
include_once('includes/functions.php');
|
||||
include_once('includes/session.php');
|
||||
|
||||
if (csrfValidateRequest() && !CSRFValidate()) {
|
||||
handleInvalidCSRFToken();
|
||||
}
|
||||
|
||||
ensureCSRFSessionToken();
|
||||
header('X-CSRF-Token', $_SESSION['csrf_token']);
|
5
includes/session.php
Normal file
5
includes/session.php
Normal file
@@ -0,0 +1,5 @@
|
||||
<?php
|
||||
|
||||
if (session_status() == PHP_SESSION_NONE) {
|
||||
session_start();
|
||||
}
|
Reference in New Issue
Block a user