ADmad
|
8eabd396df
Merge branch '4.next' into 5.x
|
4 years ago |
Mark Story
|
e9c9bbcc55
Fix TypeError on invalid base64 data.
|
4 years ago |
Corey Taylor
|
2918a44d1d
Merge branch '4.next' into 5.x
|
4 years ago |
Corey Taylor
|
acd8af5f9b
Merge branch '4.x' into 4.next
|
4 years ago |
Mark Story
|
4044e676b4
Fix TypeError in CsrfProtectionMiddleware
|
4 years ago |
Corey Taylor
|
5a77162a44
Add use statements for all fully qualified classes
|
4 years ago |
Corey Taylor
|
70caca0085
Add use statements for all fully qualified classes
|
4 years ago |
ADmad
|
8842b295df
Remove deprecated code.
|
4 years ago |
Corey Taylor
|
cb2c46e083
Fix merge errors
|
4 years ago |
Corey Taylor
|
34dad18ff5
Merge branch '4.next' into 5.0
|
4 years ago |
Corey Taylor
|
27b1080860
Add native return types in tests/
|
4 years ago |
Corey Taylor
|
8aa926d262
Merge branch '4.next' into 5.0
|
4 years ago |
Corey Taylor
|
30dab5436d
Fix return typehints in tests
|
4 years ago |
Corey Taylor
|
57473cb445
Merge branch '4.next' into 5.0
|
4 years ago |
Corey Taylor
|
3f742d563e
Fix tests param typehints
|
4 years ago |
Corey Taylor
|
048933ee36
Remove http-related deprecated code
|
4 years ago |
Mark Story
|
ca2a768018
Fix phpcs
|
5 years ago |
Mark Story
|
ce5747de81
Fix CSRF token backwards compatibility
|
5 years ago |
Mark Story
|
39b48b6a6a
Salt stateless CSRF tokens as well
|
5 years ago |
Corey Taylor
|
7013b5ed8e
Deprecate Exception::responseHeader() in favor of HttpException
|
5 years ago |
ADmad
|
e01649deb9
Add new assertion methods added in PHP 9.
|
5 years ago |
Mark Story
|
01ef3564a5
Throw an error when the csrfToken attribute is already set
|
5 years ago |
ADmad
|
a3216cf58d
Merge branch 'master' into 4.next
|
5 years ago |
Mark Story
|
b579dc8b3b
Remove more whitelist usage
|
5 years ago |
Mark Story
|
1f30a17a64
Add missing type checks to SecurityComponent and CSRF middleware.
|
5 years ago |
ADmad
|
8762b2452a
Rename option "httpOnly" to "httponly" for consistency.
|
5 years ago |
ADmad
|
301cf4d603
Allow specifying "SameSite" attribute for CSRF protection cookie.
|
5 years ago |
Edgaras Janušauskas
|
68a6ab436e
Update tests/TestCase/Http/Middleware/CsrfProtectionMiddlewareTest.php
|
6 years ago |
Edgaras Janušauskas
|
51d1aff5c8
Delete cookie with invalid CSRF token
|
6 years ago |
Mark Story
|
f70f533d07
Fix lint errors.
|
6 years ago |