Re: [RFC DRAFT] Automatic CSRF Protection

From: Date: Wed, 11 May 2016 01:11:57 +0000
Subject: Re: [RFC DRAFT] Automatic CSRF Protection
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-93183@lists.php.net to get a copy of this message
Hi Stas, On Wed, May 11, 2016 at 7:58 AM, Stanislav Malyshev <smalyshev@gmail.com> wrote: >>> Add where? And where that value would come from? RFC says nothing about >>> that. >> >> As usual. Query parameter when GET is used. Additional input when POST >> is used. All users have to do is adding CSRF token to JS program. > > GET and POST aren't the only HTTP methods. And where JS program would > get the correct token from? As far as I can see, there's no function in > the RFC that produces it. PHP doesn't have other method support yet. If users have their implementation PUT/etc, they may validate CSRF token manually. I intended this feature for simple applications that lacks CSRF protection at first, but it seems I'm better to change objective. I'll change target to semi automatic/manual CSRF protection. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#93183) next »