douyingtai6662 2018-08-04 09:00
浏览 15
已采纳

laravel如何保护从刀片到控制器的传递数据

How can I secure data from being change if user used inspect element in chrome to change id, price..etc, I know I can't prevent users from using inspect element and do changes but I dont want these changes to have effect I used this in blade to pass data from button using ajax

<button id="Item_root" data-id="{{$product->product_id}}"  data-detailsfield="{{$product->product_details}}" data-titlefield="{{$product->product_title}}" data-pricefield="{{$product->product_price}}" data-photofield="{{ asset('images/' . $product->product_image) }}" class="Item_root Button_root">

and from inspect element user can see it like this:

    <button id="Item_root" data-id="19" data-detailsfield="Serves 6-8 People" data-titlefield="Package # 8U" data-pricefield="105.99" data-photofield="http://localhost/crisp/public/images/Chicken-Fajitas.jpg" class="Item_root Button_root">
   <div class="Item_image" style="background-image:url('http://localhost/crisp/public/images/Chicken-Fajitas.jpg');"></div>
   <div class="Item_itemContent">
      <div class="Item_topSection">
         <span class="Item_name styles_just-right styles_base styles_spacing-base">Package # 8U</span>
         <span class="Item_price styles_just-right styles_base styles_spacing-base styles_semibold">$105.99</span>
      </div>
      <div class="Item_description styles_small styles_base styles_spacing-base styles_line-default">Serves 6-8 People</div>
   </div>
</button>
  • 写回答

1条回答 默认 最新

  • douzao1119 2018-08-04 09:28
    关注

    To preventing change values by users in inspect element and send it again to controller, you should use CSRF_TOKEN in input fields,

    Take a look at here:

    In laravel 5.6

    <form method="POST" action="/profile">
       @csrf
    ...
    </form>
    

    And also Laravel has Validation for check all input type that you defined.

    Here is the documerntation :

    Laravel Validation

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 安卓adb backup备份应用数据失败
  • ¥15 eclipse运行项目时遇到的问题
  • ¥15 关于#c##的问题:最近需要用CAT工具Trados进行一些开发
  • ¥15 南大pa1 小游戏没有界面,并且报了如下错误,尝试过换显卡驱动,但是好像不行
  • ¥15 没有证书,nginx怎么反向代理到只能接受https的公网网站
  • ¥50 成都蓉城足球俱乐部小程序抢票
  • ¥15 yolov7训练自己的数据集
  • ¥15 esp8266与51单片机连接问题(标签-单片机|关键词-串口)(相关搜索:51单片机|单片机|测试代码)
  • ¥15 电力市场出清matlab yalmip kkt 双层优化问题
  • ¥30 ros小车路径规划实现不了,如何解决?(操作系统-ubuntu)