Update token.php
This commit is contained in:
+30
-11
@@ -59,19 +59,38 @@ class token {
|
|||||||
*/
|
*/
|
||||||
public function create($key) {
|
public function create($key) {
|
||||||
|
|
||||||
|
//allow only specific characters
|
||||||
|
$key = preg_replace('[^a-zA-Z0-9\-_@.\/]', '', $key);
|
||||||
|
|
||||||
//create a token and save in the token session array
|
//create a token and save in the token session array
|
||||||
$_SESSION['tokens'][$key]['name'] = hash_hmac('sha256', $key, bin2hex(random_bytes(32)));
|
$_SESSION['tokens'][$key]['name'] = hash_hmac('sha256', $key, bin2hex(random_bytes(32)));
|
||||||
$_SESSION['tokens'][$key]['hash'] = hash_hmac('sha256', $key, bin2hex(random_bytes(32)));
|
$_SESSION['tokens'][$key]['hash'] = hash_hmac('sha256', $key, bin2hex(random_bytes(32)));
|
||||||
|
|
||||||
//send the hash
|
//send the hash
|
||||||
return $_SESSION['tokens'][$key]['hash'];
|
return $_SESSION['tokens'][$key];
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* validate the token
|
* validate the token
|
||||||
* @var string $key
|
* @var string $key
|
||||||
*/
|
*/
|
||||||
public function validate($key, $value) {
|
public function validate($key, $value = null) {
|
||||||
|
|
||||||
|
//allow only specific characters
|
||||||
|
$key = preg_replace('[^a-zA-Z0-9]', '', $key);
|
||||||
|
|
||||||
|
//get the token name
|
||||||
|
$token_name = $_SESSION['tokens'][$key]['name'];
|
||||||
|
if (isset($_REQUEST[$token_name])) {
|
||||||
|
$value = $_REQUEST[$token_name];
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
$value;
|
||||||
|
}
|
||||||
|
|
||||||
|
//limit the value to specific characters
|
||||||
|
$value = preg_replace('[^a-zA-Z0-9]', '', $value);
|
||||||
|
|
||||||
//compare the hashed tokens
|
//compare the hashed tokens
|
||||||
if (hash_equals($_SESSION['tokens'][$key]['hash'], $value)) {
|
if (hash_equals($_SESSION['tokens'][$key]['hash'], $value)) {
|
||||||
@@ -88,20 +107,20 @@ class token {
|
|||||||
/*
|
/*
|
||||||
|
|
||||||
//create token
|
//create token
|
||||||
$token = new token;
|
$object = new token;
|
||||||
$token_hash = $token->create('/app/users/user_edit.php');
|
$token = $object->create('/app/bridges/bridge_edit.php');
|
||||||
|
|
||||||
echo "<input type='hidden' name='token' value='".$token_hash."'>";
|
echo " <input type='hidden' name='".$token['name']."' value='".$token['hash']."'>\n";
|
||||||
|
|
||||||
//------------------------
|
//------------------------
|
||||||
|
|
||||||
//validate the token
|
//validate the token
|
||||||
$token = new token;
|
$token = new token;
|
||||||
$token_valid = $token->validate('/app/users/user_edit.php', $_POST['token']);
|
if (!$token->validate('/app/bridges/bridge_edit.php')) {
|
||||||
if (!$token_valid) {
|
$_SESSION["message"] = $text['message-invalid_token'];
|
||||||
echo "access denied";
|
header('Location: bridges.php');
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user