2016-08-18 04:05:11 +02:00
|
|
|
<?php
|
|
|
|
|
2016-08-25 03:17:58 +02:00
|
|
|
namespace Miniflux\Helper;
|
2016-08-18 04:05:11 +02:00
|
|
|
|
|
|
|
function generate_csrf()
|
|
|
|
{
|
|
|
|
if (! isset($_SESSION['csrf'])) {
|
|
|
|
$_SESSION['csrf'] = array();
|
|
|
|
}
|
|
|
|
|
|
|
|
$token = generate_token();
|
|
|
|
$_SESSION['csrf'][$token] = true;
|
|
|
|
|
|
|
|
return $token;
|
|
|
|
}
|
|
|
|
|
|
|
|
function check_csrf_values(array &$values)
|
|
|
|
{
|
|
|
|
if (empty($values['csrf']) || ! isset($_SESSION['csrf'][$values['csrf']])) {
|
|
|
|
$values = array();
|
|
|
|
} else {
|
|
|
|
unset($_SESSION['csrf'][$values['csrf']]);
|
|
|
|
unset($values['csrf']);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
function check_csrf($token)
|
|
|
|
{
|
|
|
|
if (isset($_SESSION['csrf'][$token])) {
|
|
|
|
unset($_SESSION['csrf'][$token]);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
return false;
|
|
|
|
}
|