selective/samesite-cookie
最新稳定版本:0.5.0
Composer 安装命令:
composer require selective/samesite-cookie
包简介
Secure your site with SameSite cookies
README 文档
README
A PSR-15 middleware to secure your site with SameSite cookies 🍪
Requirements
- PHP 8.1 - 8.4
Installation
composer require selective/samesite-cookie
SameSite cookies
Same-site cookies ("First-Party-Only" or "First-Party") allow servers to mitigate the risk of CSRF and information leakage attacks by asserting that a particular cookie should only be sent with requests initiated from the same registrable domain.
Warning: SameSite cookies doesn't work at all for old Browsers and also not for some Mobil Browsers e.g. IE 10, Blackberry, Opera Mini, IE Mobile, UC Browser for Android.
Further details can be found here:
- SameSite cookies explained
- CSRF is (really) dead
- PHP setcookie “SameSite=Strict”?
- How to Set a cookie attribute Samesite value in PHP ?
- Can I use SameSite?
Slim 4 integration
<?php use Selective\SameSiteCookie\SameSiteCookieMiddleware; use Slim\Factory\AppFactory; $app = AppFactory::create(); // ... // Register the samesite cookie middleware $app->add(new SameSiteCookieMiddleware()); // ... $app->run();
Example with configuration and the session starter middleware.
Slim 4 uses a LIFO (last in, first out) middleware stack, so we have to add the middleware in reverse order:
<?php use Selective\SameSiteCookie\SameSiteCookieConfiguration; use Selective\SameSiteCookie\SameSiteCookieMiddleware; use Selective\SameSiteCookie\SameSiteSessionMiddleware; use Slim\Factory\AppFactory; $app = AppFactory::create(); // ... // Optional: Add custom configuration $configuration = new SameSiteCookieConfiguration(); // Register the samesite cookie middleware $app->add(new SameSiteCookieMiddleware($configuration)); // Optional: Start the PHP session // Use this middleware only if you have no other session starter middleware $app->add(new SameSiteSessionMiddleware()); // ... $app->run();
License
The MIT License (MIT). Please see License File for more information.
统计信息
- 总下载量: 142.48k
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 10
- 点击次数: 1
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2019-09-16
