From 57f0c81f2cc0518ed7ab107e16e6cadb8dfc53b0 Mon Sep 17 00:00:00 2001
From: thomascube <thomas@roundcube.net>
Date: Wed, 15 Jul 2009 05:49:35 -0400
Subject: [PATCH] Use request tokens to protect POST requests from CSFR
---
program/include/rcmail.php | 33 +++++++++++++++++++++++++++++++++
1 files changed, 33 insertions(+), 0 deletions(-)
diff --git a/program/include/rcmail.php b/program/include/rcmail.php
index a4f44b8..627a8f2 100644
--- a/program/include/rcmail.php
+++ b/program/include/rcmail.php
@@ -852,6 +852,39 @@
/**
+ * Generate a unique token to be used in a form request
+ *
+ * @param string Request identifier
+ * @return string The request token
+ */
+ public function get_request_token($key)
+ {
+ if (!$this->request_tokens[$key])
+ $_SESSION['request_tokens'][$key] = $this->request_tokens[$key] = md5(uniqid($key . rand(), true));
+
+ return $this->request_tokens[$key];
+ }
+
+
+ /**
+ * Check if the current request contains a valid token
+ *
+ * @param string Request identifier
+ * @return boolean True if request token is valid false if not
+ */
+ public function check_request($key, $mode = RCUBE_INPUT_POST)
+ {
+ $token = get_input_value('_token', $mode);
+ $valid = !(empty($token) || $_SESSION['request_tokens'][$key] != $token);
+
+ if ($valid)
+ unset($_SESSION['request_tokens'][$key]);
+
+ return $valid;
+ }
+
+
+ /**
* Create unique authorization hash
*
* @param string Session ID
--
Gitblit v1.9.1