æåãã¬ã¼ã ã¯ã¼ã¯ã®CSRF対çæ¹æ³ã調ã¹ãã¾ã¨ã
ZendFramework
æµã
- 表示æ : tokençæâhiddenã»ãã + ã»ãã·ã§ã³ã«ã»ãã
- éä¿¡æ : éããã¦ããtokenãã»ãã·ã§ã³ã«ãããã®ã¨åããã§ãã§ãã¯
tokençææ¹æ³
ã©ã³ãã å¤ + salt + åºå®å¤ + ã©ã³ãã å¤
md5( mt_rand(1,1000000) . $this->getSalt() . $this->getName() . mt_rand(1,1000000) );
ã¾ã¨ã
ã©ã³ãã å¤ãã»ãã·ã§ã³ã«ããã¦ãéããã¦ãããã®ã¨ãã§ãã¯ã
Symfony
æµã
- 表示æ : tokençæâhiddenã»ãã
- éä¿¡æ : éããã¦ããtokenããå度çæããtokenã¨æ¯è¼ãã¦åãããã§ãã¯
tokençææ¹æ³
salt + åºå®å¤ + ã»ãã·ã§ã³ID
sha1($this->secret.$intention.$this->getSessionId());
ã¾ã¨ã
ãªãã»ã©ã»ãã·ã§ã³ID使ãã®ãã
cakephp
æµã
- 表示æ : tokençæâhiddenã»ãã + ã»ãã·ã§ã³ã«ã»ãã
- éä¿¡æ : éããã¦ããtokenãã»ãã·ã§ã³ã«ãããã®ã¨åããã§ãã§ãã¯ãæå¹æéè¨å®å¯ã
ã¾ã¨ã
ã©ã³ãã å¤ãã»ãã·ã§ã³ã«ããã¦ãéããã¦ãããã®ã¨ãã§ãã¯ã
fuelphp
æµã
- 表示æ : tokençæâhiddenã»ãã + ã¯ããã¼ã«ã»ãã
- éä¿¡æ : éããã¦ããtokenãã¯ããã¼ã«ãããã®ã¨åããã§ãã§ãã¯ãæå¹æéè¨å®å¯(=ã¯ããã¼ã®æå¹æé)ã
ã¾ã¨ã
jsã«ã対å¿ãã¦ãã®ã§jsã§ã¯ããã¼æ¸ããããããããã¯ããã¼ä½¿ã£ã¦ãã¿ããã
ruby on rails
æµã
- 表示æ : tokençæâhiddenã»ãã + ã»ãã·ã§ã³ã«ã»ãã
- éä¿¡æ : éããã¦ããtokenãã»ãã·ã§ã³ã«ãããã®ã¨åããã§ãã§ãã¯
ã¾ã¨ã
ã©ã³ãã å¤ãã»ãã·ã§ã³ã«ããã¦ãéããã¦ãããã®ã¨ãã§ãã¯ã
çµè«
ããã ãã¨ã£ã¦
- ã©ã³ãã å¤ãã»ãã·ã§ã³ã«ããã¦ãéããã¦ãããã®ã¨ãã§ãã¯
- æå¹æéãã§ãã¯
- salt + shha1ã§çæ
ãä¸çªãããããã¤ã¾ãcakeã®ãä¸çªããããã