1 | <?php |
||
2 | |||
3 | /** |
||
4 | * webtrees: online genealogy |
||
5 | * Copyright (C) 2025 webtrees development team |
||
6 | * This program is free software: you can redistribute it and/or modify |
||
7 | * it under the terms of the GNU General Public License as published by |
||
8 | * the Free Software Foundation, either version 3 of the License, or |
||
9 | * (at your option) any later version. |
||
10 | * This program is distributed in the hope that it will be useful, |
||
11 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
12 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
13 | * GNU General Public License for more details. |
||
14 | * You should have received a copy of the GNU General Public License |
||
15 | * along with this program. If not, see <https://www.gnu.org/licenses/>. |
||
16 | */ |
||
17 | |||
18 | declare(strict_types=1); |
||
19 | |||
20 | namespace Fisharebest\Webtrees\Http\Middleware; |
||
21 | |||
22 | use Fig\Http\Message\RequestMethodInterface; |
||
23 | use Fisharebest\Webtrees\FlashMessages; |
||
24 | use Fisharebest\Webtrees\Http\RequestHandlers\Logout; |
||
25 | use Fisharebest\Webtrees\Http\RequestHandlers\SelectLanguage; |
||
26 | use Fisharebest\Webtrees\Http\RequestHandlers\SelectTheme; |
||
27 | use Fisharebest\Webtrees\I18N; |
||
28 | use Fisharebest\Webtrees\Session; |
||
29 | use Fisharebest\Webtrees\Validator; |
||
30 | use Psr\Http\Message\ResponseInterface; |
||
31 | use Psr\Http\Message\ServerRequestInterface; |
||
32 | use Psr\Http\Server\MiddlewareInterface; |
||
33 | use Psr\Http\Server\RequestHandlerInterface; |
||
34 | |||
35 | use function in_array; |
||
36 | |||
37 | /** |
||
38 | * Middleware to wrap a request in a transaction. |
||
39 | */ |
||
40 | class CheckCsrf implements MiddlewareInterface |
||
41 | { |
||
42 | private const array EXCLUDE_ROUTES = [ |
||
0 ignored issues
–
show
Bug
introduced
by
![]() |
|||
43 | Logout::class, |
||
44 | SelectLanguage::class, |
||
45 | SelectTheme::class, |
||
46 | ]; |
||
47 | |||
48 | /** |
||
49 | * @param ServerRequestInterface $request |
||
50 | * @param RequestHandlerInterface $handler |
||
51 | * |
||
52 | * @return ResponseInterface |
||
53 | */ |
||
54 | public function process(ServerRequestInterface $request, RequestHandlerInterface $handler): ResponseInterface |
||
55 | { |
||
56 | if ($request->getMethod() === RequestMethodInterface::METHOD_POST) { |
||
57 | $route = Validator::attributes($request)->route(); |
||
58 | |||
59 | if (!in_array($route->name, self::EXCLUDE_ROUTES, true)) { |
||
60 | $params = (array) $request->getParsedBody(); |
||
61 | $client_token = $params['_csrf'] ?? $request->getHeaderLine('X-CSRF-TOKEN'); |
||
62 | $session_token = Session::get('CSRF_TOKEN'); |
||
63 | |||
64 | unset($params['_csrf']); |
||
65 | |||
66 | $request = $request->withParsedBody($params); |
||
67 | |||
68 | if ($client_token !== $session_token) { |
||
69 | if ($client_token === '') { |
||
70 | FlashMessages::addMessage(I18N::translate('The form data is incomplete. Perhaps you need to increase max_input_vars on your server?')); |
||
71 | } else { |
||
72 | FlashMessages::addMessage(I18N::translate('This form has expired. Try again.')); |
||
73 | } |
||
74 | |||
75 | return redirect((string) $request->getUri()); |
||
76 | } |
||
77 | } |
||
78 | } |
||
79 | |||
80 | return $handler->handle($request); |
||
81 | } |
||
82 | } |
||
83 |