mebjas / CSRF-Protector-PHP

CSRF Protector library: standalone library for CSRF mitigation
https://owasp.org/www-project-csrfprotector/
Other
211 stars 89 forks source link

Automatic Token #150

Open g7sim opened 3 years ago

g7sim commented 3 years ago

Is your feature request related to a problem? Please describe. A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]

Describe the solution you'd like A clear and concise description of what you want to happen.

Describe alternatives you've considered A clear and concise description of any alternative solutions or features you've considered.

Additional context Add any other context or screenshots about the feature request here.

g7sim commented 3 years ago

At the moment - in config.php : array -> CSRFP_TOKEN: '' name of the csrf token as it will appear in COOKIE, SESSION, GET or POST I would be simpler and safer to generate a random token by the server so that the token is not always the same. In config.php stands in test -> $cscfg = array( "CSRFP_TOKEN" => "CSRFP-Token", How can i change this value to bin2hex(random_bytes(10)) ? Can You give me a code please ( array_push($cscfg["CSRFP_TOKEN"], "bin2hex(random_bytes(10))"); doesnt change "CSRFP_TOKEN" ).