FuelPHP â CSRF対çãè¡ã
1.config.phpã®è¨å®
csrf_autoload : trueã«ããã¨èªåã§ãã§ãã¯ãè¡ããã»ã¨ãã©ã®å ´åãæåã§ãã§ãã¯ãè¡ãã®ã§falseã«ãã¦ãã
csrf_token_key
ï¼ hiddenã«ã»ãããããcsrfãã§ãã¯å¤ã®ãã¼csrf_expiration
ï¼ csrfã¯ããã¼ã®æå¹æéã0ãã大ããªå¤ã¯æå¹ãªç§æ°
Â
2.htmlã¸csrfãã¼ã®ã»ããï¼ãã§ãã¯ãè¡ãåç»é¢ï¼
echo \Form::hidden(\Config::get('security.csrf_token_key'), \Security::fetch_token());
Â
3.ãã§ãã¯
   if ( ! Security::check_token())
   {
       // CSRF æ»æã¾ã㯠CSRF ãã¼ã¯ã³ã®æéåã
   }
Â