ã¡ã¢, PHPãPHP TIPSã 58. ããããªãã¼ã対çç´¹ä»ããã¦ããã®ã¯ã·ã³ãã«ãªã¯ã³ã¿ã¤ã ãã¼ã¯ã³ï¼åç´ãªãªãã¼ã対çã§ããã° ticket ã®å¤ã¯ä¹±æ°ã§ãªãã¦ãè¯ãï¼ãããä¹±æ°ã«ãããã¨ã§ CSRF 対çãå
¼ãã¦ããï¼ãã ãã®æ¹æ³ã¯ï¼å ´åã«ãã£ã¦ã¯ãã©ã¼ã ãæ£å¸¸ã«éä¿¡ã§ããªããªã£ã¦ãã¾ãåé¡ãããï¼ ä¾ãã°ï¼å
¥åç»é¢âå
¥å確èªç»é¢ã¨é·ç§»ãã¦ããå¥ã®ã¦ã£ã³ãã¦ã§å
¥åç»é¢âå
¥å確èªç»é¢ã¨é·ç§»ããã¨ï¼åã®å
¥å確èªç»é¢ã®ãã©ã¼ã 㯠ticket ãç¡å¹ã«ãªãï¼ãã©ã¼ã ãéä¿¡ã§ããªããªãï¼è¤æ°ç»é¢åæç·¨éãã§ããªãï¼ï¼ 解決çã¨ãã¦ã¯ï¼çºè¡ãããã¼ã¯ã³ãå
¨ã¦è¨æ¶ãã¦ããï¼POST ããããã¼ã¯ã³ã¨ç
§åããæ¹æ³ãããï¼ confirm.php session_start(); $token = sha1(uniqid(mt_rand(), true)); // ãã¼ã¯ã³ãã»ãã·ã§ã³ã«è¿½å ã
{{#tags}}- {{label}}
{{/tags}}