Re: [RFC DRAFT] Automatic CSRF Protection
| From: | Yasuo Ohgaki | Date: | Wed, 11 May 2016 01:17:10 +0000 |
| Subject: | Re: [RFC DRAFT] Automatic CSRF Protection | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-93184@lists.php.net to get a copy of this message | ||
Hi Stas,
On Wed, May 11, 2016 at 7:58 AM, Stanislav Malyshev <smalyshev@gmail.com> wrote:
>>> Add where? And where that value would come from? RFC says nothing about
>>> that.
>>
>> As usual. Query parameter when GET is used. Additional input when POST
>> is used. All users have to do is adding CSRF token to JS program.
>
> GET and POST aren't the only HTTP methods. And where JS program would
> get the correct token from? As far as I can see, there's no function in
> the RFC that produces it.
JS code that does not have pages at all may obtain CSRF token manually.
get_csrf_token.php
<?php
session_start(['csrf_protection'=>SESSION_CSRF_GET]);
echo json_encode(['SESSCSRF'=>SESSCSRF]);
?>
then JS apps may use the token. Users must be careful for CSRF token TTL.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net