【发布时间】:2018-09-03 10:26:39
【问题描述】:
我需要完全禁用对我的应用程序的 CSRF 令牌的控制。 我尝试使用:
public function beforeFilter(Event $event)
{
$this->getEventManager()->off($this->Csrf);
}
在 AppController 但它似乎不起作用。 手动链接:Disabling the CSRF Component for Specific Actions
我做了很多测试,阅读了很多帖子,但我无法解决。
泰。
@omerowitz 这是我在过滤操作之前的 AppController:
public function beforeFilter(Event $event)
{
$this->getEventManager()->off($this->Security);
if($this->request->is('post')) {
$this->getEventManager()->off($this->Csrf);
}
$this->Auth->allow(['index', 'view', 'display']);
}
但它仍然不起作用,我仍然有错误“CSRF 令牌不匹配”。当我向邮递员提出请求时
解决方案:
我已经删除了这个:
->add(new CsrfProtectionMiddleware([
'httpOnly' => true
]));
来自 Application.php。 为什么手册中没有说明?
大家好!
【问题讨论】:
-
您是否在外部调用邮递员的操作?
-
每当收到错误时,请务必发布complete错误,即包括full堆栈跟踪 (最好从日志中以正确可读的方式复制) - 谢谢!我想你会发现异常不是由组件触发的,而是by the middleware。
-
是的,我要求邮递员采取行动。这是堆栈跟踪错误click
-
现在我使用的是HTTP协议,会不会有问题?
-
@DanieleCancani 也许您正在发送
PUT请求,所以只需删除条件:if($this->request->is('post')) {。
标签: cakephp-3.0