Fixing csrf generation process

This commit is contained in:
Dennis Eichhorn 2015-12-27 11:48:07 +01:00
parent 66e7eb03a6
commit 1abd8c271a

View File

@ -64,8 +64,11 @@ class HttpSession implements SessionInterface
$this->sid = session_id();
session_write_close();
$CSRF = StringUtils::generateString(10, 16);
$this->set('CSRF', $CSRF, false);
if(($CSRF = $this->get('CSRF')) === null) {
$CSRF = StringUtils::generateString(10, 16);
$this->set('CSRF', $CSRF, false);
}
UriFactory::setQuery('$CSRF', $CSRF);
}