* Enable CSRF protection by default.
This commit is contained in:
+1
-1
@@ -109,7 +109,7 @@ $config->framework->purifier = true; // 是否对数据做purifier处理
|
||||
$config->framework->logDays = 14; // 日志文件保存的天数。 The days to save log files.
|
||||
$config->framework->autoRepairTable = true;
|
||||
$config->framework->autoLang = false;
|
||||
$config->framework->filterCSRF = false;
|
||||
$config->framework->filterCSRF = true;
|
||||
$config->framework->setCookieSecure = true;
|
||||
$config->framework->sendXCTO = true; // Send X-Content-Type-Options header.
|
||||
$config->framework->sendXXP = true; // Send X-XSS-Protection header.
|
||||
|
||||
@@ -610,7 +610,8 @@ class baseRouter
|
||||
{
|
||||
$httpType = (isset($_SERVER["HTTPS"]) && $_SERVER["HTTPS"] == 'on') ? 'https' : 'http';
|
||||
$httpHost = $_SERVER['HTTP_HOST'];
|
||||
if((!defined('RUN_MODE') or RUN_MODE != 'api') and strpos($this->server->http_referer, "$httpType://$httpHost") !== 0) $_FILES = $_POST = array();
|
||||
$isAPI = (defined('RUN_MODE') && RUN_MODE == 'api') || isset($_GET[$this->config->sessionVar]);
|
||||
if(!$isAPI && strpos($this->server->http_referer, "$httpType://$httpHost") !== 0) $_FILES = $_POST = array();
|
||||
}
|
||||
|
||||
$_FILES = validater::filterFiles();
|
||||
|
||||
Reference in New Issue
Block a user