Download the PHP package maer/csrf without Composer

On this page you can find all versions of the php package maer/csrf. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package csrf

A small CSRF package for PHP

Quickly generate and validate tokens to prevent Cross-Site Request Forgery (CSRF) attacks.

Important: This package only helps you with the CSRF tokens. To truly be safe from CSRF, you also need to protect yourself against Cross-site scripting (XSS) as well.

Install

Git clone or use composer to download the package with the following command:

Usage

Include composers autoloader or include the files in the src/ folder manually. (start with CsrfInterface.php-file)

Create a new instance

Important: You can create a new instance when ever in your application, but before you make any calls to it, you need to start the session yourself. This package does not make any assumptions on how you manage your sessions (you might use: session_start() or you might use Symfonys Session package etc...)

Approach 1: Manually add the hidden field

Approach 2: Generate the hidden field

Validate

When receiving the post:

Extra goodies

Named tokens

All methods takes an optional $name argument. This gives you the option of having multiple tokens through out your application. For example:

The above will generate three different tokens and the same goes for the getTokenField()-method.

To validate named tokens, set the name as the second argument to the validateToken()-method:

Regenerate tokens

If you want to invalidate an existing token, use the regenerateToken()-method. This method also returns the new token, so if you want to have different tokens every time a form is loaded, you can use this method instead of generateToken()

Reset/remove all tokens

This will remove all tokens, named or not.

Note

If you have any questions, suggestions or issues, let me know!

Happy coding!


All versions of csrf with dependencies

PHP Build Version
Package Version
Requires php Version >=5.4.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package maer/csrf contains the following files

Loading the files please wait ....