Skip to content
This repository has been archived by the owner on Nov 9, 2017. It is now read-only.

Commit

Permalink
correct xsrf cookie/header management
Browse files Browse the repository at this point in the history
  • Loading branch information
anlutro committed Jul 17, 2015
1 parent d536ca1 commit 18a951d
Show file tree
Hide file tree
Showing 2 changed files with 23 additions and 3 deletions.
6 changes: 4 additions & 2 deletions src/Web/Filters/CsrfFilter.php
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,11 @@ public function __construct(Store $session, $regenerate = true)
public function filter(Route $route, Request $request)
{
$token = $request->input('_token');

if (!$token) {
$token = $request->cookie('X-XSRF-TOKEN');
$token = $request->headers->get('X-XSRF-TOKEN');
}
if (!$token) {
$token = $request->cookie('XSRF-TOKEN');
}

if (!StringUtils::equals($this->session->token(), $token)) {
Expand Down
20 changes: 19 additions & 1 deletion tests/Web/Filters/CsrfFilterTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,24 @@ public function readsInputToken($throws, $input, $sessionToken)
$filter->filter($route, $request);
}

/**
* @test
* @dataProvider getTokenData
*/
public function readsHeaderToken($throws, $input, $sessionToken)
{
$route = $this->mockRoute();
$request = Request::create('/', 'POST', []);
$request->headers->set('X-XSRF-TOKEN', $input);
$session = $this->mockSession();
$session->shouldReceive('token')->andReturn($sessionToken);
$filter = $this->makeFilter($session, false);
if ($throws) {
$this->setExpectedException('Illuminate\Session\TokenMismatchException');
}
$filter->filter($route, $request);
}

/**
* @test
* @dataProvider getTokenData
Expand All @@ -50,7 +68,7 @@ public function readsCookieToken($throws, $input, $sessionToken)
{
$route = $this->mockRoute();
$request = Request::create('/', 'POST', []);
$request->cookies->set('X-XSRF-TOKEN', $input);
$request->cookies->set('XSRF-TOKEN', $input);
$session = $this->mockSession();
$session->shouldReceive('token')->andReturn($sessionToken);
$filter = $this->makeFilter($session, false);
Expand Down

0 comments on commit 18a951d

Please sign in to comment.