* Enable CSRF protection by default.

This commit is contained in:
zhujinyong
2021-08-10 14:02:41 +08:00
parent c4b9c9ef3c
commit cb40696190
2 changed files with 3 additions and 2 deletions
+1 -1
View File
@@ -109,7 +109,7 @@ $config->framework->purifier = true; // 是否对数据做purifier处理
$config->framework->logDays = 14; // 日志文件保存的天数。 The days to save log files.
$config->framework->autoRepairTable = true;
$config->framework->autoLang = false;
$config->framework->filterCSRF = false;
$config->framework->filterCSRF = true;
$config->framework->setCookieSecure = true;
$config->framework->sendXCTO = true; // Send X-Content-Type-Options header.
$config->framework->sendXXP = true; // Send X-XSS-Protection header.
+2 -1
View File
@@ -610,7 +610,8 @@ class baseRouter
{
$httpType = (isset($_SERVER["HTTPS"]) && $_SERVER["HTTPS"] == 'on') ? 'https' : 'http';
$httpHost = $_SERVER['HTTP_HOST'];
if((!defined('RUN_MODE') or RUN_MODE != 'api') and strpos($this->server->http_referer, "$httpType://$httpHost") !== 0) $_FILES = $_POST = array();
$isAPI = (defined('RUN_MODE') && RUN_MODE == 'api') || isset($_GET[$this->config->sessionVar]);
if(!$isAPI && strpos($this->server->http_referer, "$httpType://$httpHost") !== 0) $_FILES = $_POST = array();
}
$_FILES = validater::filterFiles();