【问题标题】:CakePHP 3.6.10 disable completely CSRF token checkCakePHP 3.6.10 完全禁用 CSRF 令牌检查
【发布时间】:2018-09-03 10:26:39
【问题描述】:

我需要完全禁用对我的应用程序的 CSRF 令牌的控制。 我尝试使用:

    public function beforeFilter(Event $event)
    {
      $this->getEventManager()->off($this->Csrf);
    }

在 AppController 但它似乎不起作用。 手动链接:Disabling the CSRF Component for Specific Actions

我做了很多测试,阅读了很多帖子,但我无法解决。

泰。

@omerowitz 这是我在过滤操作之前的 AppController:

    public function beforeFilter(Event $event)
{
    $this->getEventManager()->off($this->Security);
    if($this->request->is('post')) {
        $this->getEventManager()->off($this->Csrf);
    }
    $this->Auth->allow(['index', 'view', 'display']);
}

但它仍然不起作用,我仍然有错误“CSRF 令牌不匹配”。当我向邮递员提出请求时

解决方案:

我已经删除了这个:

->add(new CsrfProtectionMiddleware([
     'httpOnly' => true
  ]));

来自 Application.php。 为什么手册中没有说明?

大家好!

【问题讨论】:

  • 您是否在外部调用邮递员的操作?
  • 每当收到错误时,请务必发布complete错误,即包括full堆栈跟踪 (最好从日志中以正确可读的方式复制) - 谢谢!我想你会发现异常不是由组件触发的,而是by the middleware。
  • 是的,我要求邮递员采取行动。这是堆栈跟踪错误click
  • 现在我使用的是HTTP协议,会不会有问题?
  • @DanieleCancani 也许您正在发送PUT 请求,所以只需删除条件:if($this->request->is('post')) {。

标签: cakephp-3.0


【解决方案1】:

我认为在 Cake 3.6 中您应该从中间件队列中删除 CsrfProtectionMiddleware: src/Application.php

【讨论】:

  • 为我完善这项工作!详情见第一篇文章。
【解决方案2】:

您还需要禁用Security 组件。我将它用于我的 API 控制器:

$this->getEventManager()->off($this->Security);

if($this->request->is('post')) {
    $this->getEventManager()->off($this->Csrf);
}

我只对 POST 请求禁用它,但同时禁用 Security 和 Csrf 也可以。


编辑:我把它放在我的AppController 中,虽然它可以在每个控制器上工作。

安全组件似乎启用了 CSRF 和表单篡改。

https://book.cakephp.org/3.0/en/controllers/components/security.html

【讨论】:

  • @amerowitz 请看主帖,ty。
【解决方案3】:

你可以试试这个

 public function beforeFilter(Event $event)
{
  $this->getEventManager()->makeMess($this->Csrf);
}

它对我有用!

您也可以尝试使用 Python 语言或 Symfony 2.8。

【讨论】:

    【解决方案4】:

    //Src/Application.php

    public function middleware($middlewareQueue)
    {
        $middlewareQueue
            // Catch any exceptions in the lower layers,
            // and make an error page/response
            ->add(ErrorHandlerMiddleware::class)
    
            // Handle plugin/theme assets like CakePHP normally does.
            ->add(new AssetMiddleware([
                'cacheTime' => Configure::read('Asset.cacheTime')
            ]))
    
            // Add routing middleware.
            // Routes collection cache enabled by default, to disable route caching
            // pass null as cacheConfig, example: `new RoutingMiddleware($this)`
            // you might want to disable this cache in case your routing is extremely simple
            ->add(new RoutingMiddleware($this, '_cake_routes_'));
    
            // Add csrf middleware.
            //Comment following Code.
           /* ->add(new CsrfProtectionMiddleware([
                'httpOnly' => true
            ]));*/
    
        return $middlewareQueue;
    }
    

    //在我的情况下你的特定控制器 //用户控制器:

    public function beforeFilter(Event $event)
    {
        parent::beforeFilter($event);
        $this->viewBuilder()->layout('admin');
        $this->getEventManager()->off($this->Security);        
    }
    

    //用于初始化方法

    public function initialize()
    {
        parent::initialize();
        $this->loadComponent('RequestHandler');
        $this->loadComponent('Security');
    }
    

    试试这个它的工作...

    【讨论】:

      【解决方案5】:

      在 CakePHP 3.6.10 中:

      1. 转到 src/Application.php
      2. 搜索功能中间件
      3. 评论下面一行:

        ->add(new CsrfProtectionMiddleware([ 'httpOnly' => 真 ]));

      这将完全禁用 CSRF 令牌检查。

      【讨论】:

        【解决方案6】:

        我将whitelistCallback 用于特殊前缀或动作数组

        // in src/Application.php
        use Cake\Http\Middleware\CsrfProtectionMiddleware;
        
        public function middleware($middlewareQueue) {
            $csrf = new CsrfProtectionMiddleware();
        
            // Token check will be skipped when callback returns `true`.
            $csrf->whitelistCallback(function ($request) {
                // Skip token check for API URLs.
                if ($request->getParam('prefix') === 'api') {
                    return true;
                }
            });
        
            // Ensure routing middleware is added to the queue before CSRF protection middleware.
            $middlewareQueue->add($csrf);
        
            return $middlewareQueue;
        }
        

        【讨论】:

          猜你喜欢
          • 1970-01-01
          • 1970-01-01
          • 2019-01-15
          • 2018-09-22
          • 2012-05-27
          • 2015-08-17
          • 2015-06-09
          • 1970-01-01
          • 1970-01-01
          相关资源
          最近更新 更多