1 | <?php |
||
34 | class CsrfHandler |
||
35 | { |
||
36 | use SessionRequestAwareTrait; |
||
37 | |||
38 | /** |
||
39 | * FailResponder |
||
40 | * |
||
41 | * @var callable |
||
42 | * |
||
43 | * @access protected |
||
44 | */ |
||
45 | protected $failResponder; |
||
46 | |||
47 | /** |
||
48 | * Create a CSRF Handler |
||
49 | * |
||
50 | * @param callabel $failResponder respond to failed CSRF check |
||
51 | * |
||
52 | * @access public |
||
53 | */ |
||
54 | 9 | public function __construct(callable $failResponder = null) |
|
58 | |||
59 | /** |
||
60 | * Check non-idempotent and non-ignored requests and respond or continue |
||
61 | * |
||
62 | * @param Request $request PSR7 Request |
||
63 | * @param Response $response PSR7 Response |
||
64 | * @param callable $next Next callable middleware |
||
65 | * |
||
66 | * @return Response |
||
67 | * |
||
68 | * @access public |
||
69 | */ |
||
70 | 9 | public function __invoke(Request $request, Response $response, callable $next) |
|
85 | |||
86 | /** |
||
87 | * Check body for posted value, and move to request header |
||
88 | * |
||
89 | * @param Request $request PSR7 Request |
||
90 | * |
||
91 | * @return Request |
||
92 | * |
||
93 | * @access protected |
||
94 | */ |
||
95 | 8 | protected function withCsrfHeader(Request $request) |
|
111 | |||
112 | /** |
||
113 | * Ignore this request? |
||
114 | * |
||
115 | * @param Request $request PSR7 Request |
||
116 | * |
||
117 | * @return bool |
||
118 | * |
||
119 | * @access protected |
||
120 | */ |
||
121 | 8 | protected function ignore(Request $request) |
|
125 | |||
126 | /** |
||
127 | * Is CSRF Header Valid? |
||
128 | * |
||
129 | * @param Request $request PSR7 Request |
||
130 | * |
||
131 | * @return bool |
||
132 | * |
||
133 | * @access protected |
||
134 | */ |
||
135 | 7 | protected function isValid(Request $request) |
|
143 | |||
144 | /** |
||
145 | * Respond to failed CSRF Check |
||
146 | * |
||
147 | * @param Request $request PSR7 Request |
||
148 | * @param Response $response PSR7 Response |
||
149 | * |
||
150 | * @return Response |
||
151 | * |
||
152 | * @access protected |
||
153 | */ |
||
154 | 5 | protected function fail(Request $request, Response $response) |
|
164 | } |
||
165 |