Table of Contents
Reply content:
Home Backend Development PHP Tutorial javascript - How to add csrf protection to a spa that is regarded as a static resource?

javascript - How to add csrf protection to a spa that is regarded as a static resource?

Oct 22, 2016 am 12:14 AM
javascript php react-router react.js

Recently I am using react+react-router to develop spa, and I use yii2 in the background. nignx is set to return index.html when 404. But one problem with this situation is that I cannot use the protection of csrf. How to solve this situation?

I saw a website using a technology stack similar to mine. I saw that it wrote a meta tag containing the token value on the head tag, and every request it made would use this token as The value of header is sent back. How to do this? How to render the token value into this index.html?

Reply content:

Recently I am using react+react-router to develop spa, and the backend is yii2. nignx is set to return index.html when 404. But one problem with this situation is that I cannot use the protection of csrf. How to solve this situation?

I saw a website using a technology stack similar to mine. I saw that it wrote a meta tag containing the token value on the head tag, and every request it made would use this token as The value of header is sent back. How to do this? How to render the token value into this index.html?

Submitted by

ajax

1

2

3

4

5

6

7

8

9

10

<code>$.ajax({

url: 你的url

type:依什么方式

dataType:数据类型

data :

headers:{'X-CSRF-TOKEN': $('meta[name="csrf-token"]').attr('content') ? $('meta[name="csrf-token"]').attr('content') : ''},

beforeSend:function(msg){

alert('等待回调');

},

})</code>

Copy after login

Put the output part in the header

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

27

28

29

30

31

32

33

34

35

36

37

38

39

40

41

42

43

44

45

46

47

48

49

50

51

52

53

54

55

56

57

58

59

60

61

62

63

64

65

66

67

68

69

70

71

72

73

74

75

76

77

78

79

80

81

82

83

84

85

86

87

88

89

90

91

92

93

94

95

96

97

98

99

100

101

102

103

104

105

106

107

108

109

110

111

112

113

114

115

116

117

118

119

120

121

122

123

124

125

126

127

128

129

130

131

132

133

134

135

136

137

138

139

140

141

<code><?php

 

// +----------------------------------------------------------------------

// | CSRF安全验证类 @pushaowei

// +----------------------------------------------------------------------

// | [Usage]

// |    // 后端

// |    use library\Base\NoCSRF;

// |    session_start();  

// |    if ($this->getRequest()->isPost()) {

// |           

// |        try {

// |            ##验证TOKEN 

// |            NoCSRF::check( 'csrf_token', $_POST, true, 60*10, false ); //60*10为10分钟(null为不验证时间)

// |            $result = 'CSRF check passed. Form parsed.';

// |            //$this->getRequest()->getPost('field');

// |            echo $result;      

// |        } catch ( Exception $e ) {

// |            echo $e->getMessage() . ' Form ignored.';

// |        }     

// |    } else {  

// |        #生成TOKEN 

// |        $token = NoCSRF::generate( 'csrf_token' );

// |        $this->getView()->assign('token', $token);

// |        $this->getView()->display('页面');

// |    }

// |    // 前端

// |    <meta name="csrf-token" content="<?php echo library\Base\NoCSRF::generate( 'csrf_token' );?>" />

// +----------------------------------------------------------------------

 

class NoCSRF

{

    protected static $doOriginCheck = false;

    /**

     * Check CSRF tokens match between session and $origin.

     * Make sure you generated a token in the form before checking it.

     *

     * @param String $key The session and $origin key where to find the token.

     * @param Mixed $origin The object/associative array to retreive the token data from (usually $_POST).

     * @param Boolean $throwException (Facultative) TRUE to throw exception on check fail, FALSE or default to return false.

     * @param Integer $timespan (Facultative) Makes the token expire after $timespan seconds. (null = never)

     * @param Boolean $multiple (Facultative) Makes the token reusable and not one-time. (Useful for ajax-heavy requests).

     *

     * @return Boolean Returns FALSE if a CSRF attack is detected, TRUE otherwise.

     */

    public static function check( $key, $origin, $throwException=false, $timespan=null, $multiple=false )

    {

        $session = Session::getInstance();

 

        if ( !$session->has( 'csrf_' . $key ) )

            if($throwException)

                throw new \Exception( 'Missing CSRF session token.' );

            else

                return false;

             

        if ( !isset( $origin[ $key ] ) )

            if($throwException)

                throw new \Exception( 'Missing CSRF form token.' );

            else

                return false;

 

        // Get valid token from session

        $hash = $session->get('csrf_' . $key);

         

        // Free up session token for one-time CSRF token usage.

        if(!$multiple)

            $session->forget('csrf_' . $key);

 

        // Origin checks

        if( self::$doOriginCheck && sha1( $_SERVER['REMOTE_ADDR'] . $_SERVER['HTTP_USER_AGENT'] ) != substr( base64_decode( $hash ), 10, 40 ) )

        {

            if($throwException)

                throw new \Exception( 'Form origin does not match token origin.' );

            else

                return false;

        }

         

        // Check if session token matches form token

        if ( $origin[ $key ] != $hash )

            if($throwException)

                throw new \Exception( 'Invalid CSRF token.' );

            else

                return false;

 

        // Check for token expiration

        if ( $timespan != null && is_int( $timespan ) && intval( substr( base64_decode( $hash ), 0, 10 ) ) + $timespan < time() )

            if($throwException)

                throw new \Exception( 'CSRF token has expired.' );

            else

                return false;

 

        return true;

    }

 

    /**

     * Adds extra useragent and remote_addr checks to CSRF protections.

     */

    public static function enableOriginCheck()

    {

        self::$doOriginCheck = true;

    }

 

    /**

     * CSRF token generation method. After generating the token, put it inside a hidden form field named $key.

     *

     * @param String $key The session key where the token will be stored. (Will also be the name of the hidden field name)

     * @return String The generated, base64 encoded token.

     */

    public static function generate( $key )

    {

        $session = Session::getInstance();

 

        $extra = self::$doOriginCheck ? sha1( $_SERVER['REMOTE_ADDR'] . $_SERVER['HTTP_USER_AGENT'] ) : '';

        // token generation (basically base64_encode any random complex string, time() is used for token expiration)

        $token = base64_encode( time() . $extra . self::randomString( 32 ) );

        // store the one-time token in session

        $session->put('csrf_' . $key, $token);

 

        return $token;

    }

 

    /**

     * Generates a random string of given $length.

     *

     * @param Integer $length The string length.

     * @return String The randomly generated string.

     */

    protected static function randomString( $length )

    {

        $seed = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijqlmnopqrtsuvwxyz0123456789';

        $max = strlen( $seed ) - 1;

 

        $string = '';

        for ( $i = 0; $i < $length; ++$i )

            $string .= $seed{intval( mt_rand( 0.0, $max ) )};

 

        return $string;

    }

 

}

?></code>

Copy after login
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Roblox: Bubble Gum Simulator Infinity - How To Get And Use Royal Keys
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Nordhold: Fusion System, Explained
1 months ago By 尊渡假赌尊渡假赌尊渡假赌
Mandragora: Whispers Of The Witch Tree - How To Unlock The Grappling Hook
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Clair Obscur: Expedition 33 - How To Get Perfect Chroma Catalysts
2 weeks ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1677
14
PHP Tutorial
1278
29
C# Tutorial
1257
24
PHP and Python: Different Paradigms Explained PHP and Python: Different Paradigms Explained Apr 18, 2025 am 12:26 AM

PHP is mainly procedural programming, but also supports object-oriented programming (OOP); Python supports a variety of paradigms, including OOP, functional and procedural programming. PHP is suitable for web development, and Python is suitable for a variety of applications such as data analysis and machine learning.

PHP: Handling Databases and Server-Side Logic PHP: Handling Databases and Server-Side Logic Apr 15, 2025 am 12:15 AM

PHP uses MySQLi and PDO extensions to interact in database operations and server-side logic processing, and processes server-side logic through functions such as session management. 1) Use MySQLi or PDO to connect to the database and execute SQL queries. 2) Handle HTTP requests and user status through session management and other functions. 3) Use transactions to ensure the atomicity of database operations. 4) Prevent SQL injection, use exception handling and closing connections for debugging. 5) Optimize performance through indexing and cache, write highly readable code and perform error handling.

PHP's Purpose: Building Dynamic Websites PHP's Purpose: Building Dynamic Websites Apr 15, 2025 am 12:18 AM

PHP is used to build dynamic websites, and its core functions include: 1. Generate dynamic content and generate web pages in real time by connecting with the database; 2. Process user interaction and form submissions, verify inputs and respond to operations; 3. Manage sessions and user authentication to provide a personalized experience; 4. Optimize performance and follow best practices to improve website efficiency and security.

Choosing Between PHP and Python: A Guide Choosing Between PHP and Python: A Guide Apr 18, 2025 am 12:24 AM

PHP is suitable for web development and rapid prototyping, and Python is suitable for data science and machine learning. 1.PHP is used for dynamic web development, with simple syntax and suitable for rapid development. 2. Python has concise syntax, is suitable for multiple fields, and has a strong library ecosystem.

PHP and Python: A Deep Dive into Their History PHP and Python: A Deep Dive into Their History Apr 18, 2025 am 12:25 AM

PHP originated in 1994 and was developed by RasmusLerdorf. It was originally used to track website visitors and gradually evolved into a server-side scripting language and was widely used in web development. Python was developed by Guidovan Rossum in the late 1980s and was first released in 1991. It emphasizes code readability and simplicity, and is suitable for scientific computing, data analysis and other fields.

Why Use PHP? Advantages and Benefits Explained Why Use PHP? Advantages and Benefits Explained Apr 16, 2025 am 12:16 AM

The core benefits of PHP include ease of learning, strong web development support, rich libraries and frameworks, high performance and scalability, cross-platform compatibility, and cost-effectiveness. 1) Easy to learn and use, suitable for beginners; 2) Good integration with web servers and supports multiple databases; 3) Have powerful frameworks such as Laravel; 4) High performance can be achieved through optimization; 5) Support multiple operating systems; 6) Open source to reduce development costs.

PHP's Impact: Web Development and Beyond PHP's Impact: Web Development and Beyond Apr 18, 2025 am 12:10 AM

PHPhassignificantlyimpactedwebdevelopmentandextendsbeyondit.1)ItpowersmajorplatformslikeWordPressandexcelsindatabaseinteractions.2)PHP'sadaptabilityallowsittoscaleforlargeapplicationsusingframeworkslikeLaravel.3)Beyondweb,PHPisusedincommand-linescrip

PHP vs. Python: Use Cases and Applications PHP vs. Python: Use Cases and Applications Apr 17, 2025 am 12:23 AM

PHP is suitable for web development and content management systems, and Python is suitable for data science, machine learning and automation scripts. 1.PHP performs well in building fast and scalable websites and applications and is commonly used in CMS such as WordPress. 2. Python has performed outstandingly in the fields of data science and machine learning, with rich libraries such as NumPy and TensorFlow.

See all articles