Mercurial > hg > isophonics-drupal-site
view core/lib/Drupal/Core/PageCache/DefaultRequestPolicy.php @ 13:5fb285c0d0e3
Update Drupal core to 8.4.7 via Composer. Security update; I *think* we've
been lucky to get away with this so far, as we don't support self-registration
which seems to be used by the so-called "drupalgeddon 2" attack that 8.4.5
was vulnerable to.
author | Chris Cannam |
---|---|
date | Mon, 23 Apr 2018 09:33:26 +0100 |
parents | 4c8ae668cc8c |
children |
line wrap: on
line source
<?php namespace Drupal\Core\PageCache; use Drupal\Core\PageCache\RequestPolicy\CommandLineOrUnsafeMethod; use Drupal\Core\PageCache\RequestPolicy\NoSessionOpen; use Drupal\Core\Session\SessionConfigurationInterface; /** * The default page cache request policy. * * Delivery of cached pages is denied if either the application is running from * the command line or the request was not initiated with a safe method (GET or * HEAD). Also caching is only allowed for requests without a session cookie. */ class DefaultRequestPolicy extends ChainRequestPolicy { /** * Constructs the default page cache request policy. * * @param \Drupal\Core\Session\SessionConfigurationInterface $session_configuration * The session configuration. */ public function __construct(SessionConfigurationInterface $session_configuration) { $this->addPolicy(new CommandLineOrUnsafeMethod()); $this->addPolicy(new NoSessionOpen($session_configuration)); } }