dsljpwi494719 2010-09-18 10:14
浏览 20
已采纳

Zend form_element_hash

When generating a hash for a form token, I've seen a few different versions:

$hash = new Zend_Form_Element_Hash('hihacker', array('salt' => 'exitsalt'));

and 

$hash = new Zend_Form_Element_Hash('hash', 'no_csrf_foo', array('salt' => 'unique'));

First of all, does the salt have to be unique for each form render? The second one suggests so, but I'm not sure.

Also which is the better way of doing it?

  • 写回答

1条回答 默认 最新

  • dsarttv037029 2010-09-18 15:14
    关注

    A unique salt would be better, as it would change each time making it nearly impossible for any would be spammers to auto submit your form.

    Even with a constant salt, any would be hacker would be unlikely to be able to break this.

    I would suggest creating the element this way

     $hash = new Zend_Form_Element_Hash('hash', 'no_csrf_foo', array('salt' => 'unique'));
    

    This way you know that the name of the element is no_csrf_foo, so you can easily get it back later if need be by doing

    $form->getElement("no_csrf_foo");
    

    Is there some specific scenario you are afraid of that would make this method of stopping auto form submission insufficient?

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥60 版本过低apk如何修改可以兼容新的安卓系统
  • ¥25 由IPR导致的DRIVER_POWER_STATE_FAILURE蓝屏
  • ¥50 有数据,怎么建立模型求影响全要素生产率的因素
  • ¥50 有数据,怎么用matlab求全要素生产率
  • ¥15 TI的insta-spin例程
  • ¥15 完成下列问题完成下列问题
  • ¥15 C#算法问题, 不知道怎么处理这个数据的转换
  • ¥15 YoloV5 第三方库的版本对照问题
  • ¥15 请完成下列相关问题!
  • ¥15 drone 推送镜像时候 purge: true 推送完毕后没有删除对应的镜像,手动拷贝到服务器执行结果正确在样才能让指令自动执行成功删除对应镜像,如何解决?