Skip diagnostic CSRF warning if the user is not logged in

This commit is contained in:
Kijin Sung 2017-03-13 16:41:57 +09:00
parent 9a34341759
commit df59e541c9

View file

@ -321,7 +321,11 @@ class Security
}
else
{
trigger_error('CSRF token missing in POST request: ' . (\Context::get('act') ?: '(no act)'), \E_USER_WARNING);
if (Session::getMemberSrl())
{
trigger_error('CSRF token missing in POST request: ' . (\Context::get('act') ?: '(no act)'), \E_USER_WARNING);
}
$referer = strval($referer ?: $_SERVER['HTTP_REFERER']);
if ($referer !== '')
{