rhymix/common/framework
Kijin Sung e423cba24d Use Origin header before Referer to check CSRF
OWASP에서는 Referer 헤더보다 Origin 헤더를 먼저 체크하는 것을 권장합니다.
Referer가 비어 있는 경우에도 Origin 헤더에는 유용한 정보가 들어 있을 수 있기 때문입니다.

https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html
2021-02-23 16:51:46 +09:00
..
drivers Support either/both username and password for Redis #1602 2021-02-05 21:04:20 +09:00
exceptions Initial implementation of DB class based on PDO MySQL driver 2020-06-29 15:45:01 +09:00
filters Remove excess dots from filenames #1251 2020-04-16 17:46:39 +09:00
helpers Fix #1610 memory leak in initial debug status check 2021-02-10 00:27:04 +09:00
parsers Add 'ifvar' attribute to most query elements 2021-02-09 21:58:07 +09:00
cache.php Provide incr() and decr() as static methods of Cache class 2020-12-15 02:13:38 +09:00
calendar.php Fix short array syntax and backwards test 2016-03-17 17:41:03 +09:00
config.php Stop providing XE-compatible $db_info and db.config.php 2020-09-29 00:55:10 +09:00
datetime.php Implement default timezone for domains 2017-03-13 12:51:24 +09:00
db.php Use savepoints for nested transactions 2021-02-04 16:39:09 +09:00
debug.php Fix #1610 memory leak in initial debug status check 2021-02-10 00:27:04 +09:00
exception.php Add basic exception class 2016-02-01 20:11:46 +09:00
formatter.php Fix various warnings in PHP 8.0 2021-01-28 22:32:56 +09:00
i18n.php Add functions for converting between country codes and calling codes 2020-03-18 21:02:23 +09:00
image.php Storage::getContentType() 메소드를 MIME 클래스로 이동함 2019-10-09 15:20:19 +09:00
korea.php Improve validation and formatting for 0303 and 0505 phone numbers 2019-05-13 15:34:09 +09:00
lang.php Adjust loading priority of modules vs. plugins 2021-01-21 00:44:35 +09:00
mail.php Fix some obvious compatibility issues with new dependencies 2018-10-18 14:10:02 +09:00
mime.php Add MIME types for common executables and package formats 2020-03-24 01:07:07 +09:00
pagination.php Add pagination class 2016-03-17 19:46:32 +09:00
password.php Fix remainder of unit test warnings in PHP 8.0 2021-01-29 00:36:24 +09:00
push.php Add missing return type declarations to Push class 2020-12-11 19:58:22 +09:00
router.php Fix various warnings in PHP 8.0 2021-01-28 22:32:56 +09:00
security.php Use Origin header before Referer to check CSRF 2021-02-23 16:51:46 +09:00
session.php Fix #1610 memory leak in initial debug status check 2021-02-10 00:27:04 +09:00
sms.php Fix remainder of unit test warnings in PHP 8.0 2021-01-29 00:36:24 +09:00
storage.php Use RX_WINDOWS constant in core and file module 2020-02-14 16:16:33 +09:00
timer.php Fix short array syntax 2016-03-17 17:33:58 +09:00
ua.php Fix various warnings in PHP 8.0 2021-01-28 22:32:56 +09:00
url.php Fix various warnings in PHP 8.0 2021-01-28 22:32:56 +09:00