enable/disable CSRF
This commit is contained in:
parent
7fb08eb76f
commit
8908f4bdc3
@ -22,6 +22,8 @@ class Csrf
|
|||||||
|
|
||||||
public static function check($token)
|
public static function check($token)
|
||||||
{
|
{
|
||||||
|
global $config;
|
||||||
|
if($config['csrf_enabled'] == 'yes') {
|
||||||
if (isset($_SESSION['csrf_token'], $_SESSION['csrf_token_time'], $token)) {
|
if (isset($_SESSION['csrf_token'], $_SESSION['csrf_token_time'], $token)) {
|
||||||
$storedToken = $_SESSION['csrf_token'];
|
$storedToken = $_SESSION['csrf_token'];
|
||||||
$tokenTime = $_SESSION['csrf_token_time'];
|
$tokenTime = $_SESSION['csrf_token_time'];
|
||||||
@ -35,6 +37,8 @@ class Csrf
|
|||||||
}
|
}
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
public static function generateAndStoreToken()
|
public static function generateAndStoreToken()
|
||||||
{
|
{
|
||||||
|
Loading…
x
Reference in New Issue
Block a user