Mercurial > hg > isophonics-drupal-site
view core/modules/system/src/Controller/CsrfTokenController.php @ 13:5fb285c0d0e3
Update Drupal core to 8.4.7 via Composer. Security update; I *think* we've
been lucky to get away with this so far, as we don't support self-registration
which seems to be used by the so-called "drupalgeddon 2" attack that 8.4.5
was vulnerable to.
author | Chris Cannam |
---|---|
date | Mon, 23 Apr 2018 09:33:26 +0100 |
parents | 4c8ae668cc8c |
children |
line wrap: on
line source
<?php namespace Drupal\system\Controller; use Drupal\Core\Access\CsrfRequestHeaderAccessCheck; use Drupal\Core\Access\CsrfTokenGenerator; use Drupal\Core\DependencyInjection\ContainerInjectionInterface; use Symfony\Component\DependencyInjection\ContainerInterface; use Symfony\Component\HttpFoundation\Response; /** * Returns responses for CSRF token routes. */ class CsrfTokenController implements ContainerInjectionInterface { /** * The CSRF token generator. * * @var \Drupal\Core\Access\CsrfTokenGenerator */ protected $tokenGenerator; /** * Constructs a new CsrfTokenController object. * * @param \Drupal\Core\Access\CsrfTokenGenerator $token_generator * The CSRF token generator. */ public function __construct(CsrfTokenGenerator $token_generator) { $this->tokenGenerator = $token_generator; } /** * {@inheritdoc} */ public static function create(ContainerInterface $container) { return new static( $container->get('csrf_token') ); } /** * Returns a CSRF protecting session token. * * @return \Symfony\Component\HttpFoundation\Response * The response object. */ public function csrfToken() { return new Response($this->tokenGenerator->get(CsrfRequestHeaderAccessCheck::TOKEN_KEY), 200, ['Content-Type' => 'text/plain']); } }