From e86345de5f2e293e51873768dff9f0a0fe5c48b6 Mon Sep 17 00:00:00 2001 From: David McReynolds Date: Wed, 29 Jan 2020 12:49:45 -0800 Subject: [PATCH 1/2] fix: for CSRF when viewing additional pages --- fuel/modules/fuel/libraries/Form_builder.php | 2 + .../fuel/libraries/Fuel_base_controller.php | 61 +++++++++++++++++-- 2 files changed, 57 insertions(+), 6 deletions(-) diff --git a/fuel/modules/fuel/libraries/Form_builder.php b/fuel/modules/fuel/libraries/Form_builder.php index 6a7198bac..401051b10 100644 --- a/fuel/modules/fuel/libraries/Form_builder.php +++ b/fuel/modules/fuel/libraries/Form_builder.php @@ -235,6 +235,8 @@ public function reset() $this->css = array(); $this->_pre_process = array(); $this->_post_process = array(); + $this->key_check = NULL; + $this->key_check_name = NULL; } // -------------------------------------------------------------------- diff --git a/fuel/modules/fuel/libraries/Fuel_base_controller.php b/fuel/modules/fuel/libraries/Fuel_base_controller.php index a4b88f4c6..502a8c68e 100644 --- a/fuel/modules/fuel/libraries/Fuel_base_controller.php +++ b/fuel/modules/fuel/libraries/Fuel_base_controller.php @@ -121,7 +121,7 @@ protected function _validate_user($permission, $type = '', $show_error = TRUE) */ protected function _generate_csrf_token() { - return md5(uniqid(mt_rand(), TRUE)); + return $this->security->xss_hash(); } // -------------------------------------------------------------------- @@ -134,7 +134,7 @@ protected function _generate_csrf_token() */ protected function _get_csrf_token_name() { - return $this->security->get_csrf_token_name(); + return $this->security->get_csrf_token_name().'_FUEL'; } // -------------------------------------------------------------------- @@ -147,23 +147,72 @@ protected function _get_csrf_token_name() */ protected function _prep_csrf() { - $hash = $this->_generate_csrf_token(); + // The session CSRF is only created once otherwise we'll + // have issues with inline module editing and elsewhere + if (!$this->_has_session_csrf()) + { + $hash = $this->_generate_csrf_token(); + $this->_set_session_csrf($hash); + } + else + { + $hash = $this->_session_csrf(); + } + $this->form_builder->key_check_name = $this->_get_csrf_token_name(); $this->form_builder->key_check = $hash; - $_SESSION[$this->form_builder->key_check_name] = $hash; + } + + // -------------------------------------------------------------------- + + /** + * Determines if the session CSRF exists + * + * @access protected + * @return void + */ + protected function _has_session_csrf() + { + return isset($_SESSION[$this->fuel->auth->get_session_namespace()][$this->_get_csrf_token_name()]); + } + + // -------------------------------------------------------------------- + + /** + * Sets the session CSRF + * + * @access protected + * @return void + */ + protected function _set_session_csrf($hash) + { + $_SESSION[$this->fuel->auth->get_session_namespace()][$this->_get_csrf_token_name()] = $hash; + } + + // -------------------------------------------------------------------- + + /** + * Returns the session CSRF + * + * @access protected + * @return void + */ + protected function _session_csrf() + { + return !empty($_SESSION[$this->fuel->auth->get_session_namespace()][$this->_get_csrf_token_name()]) ? $_SESSION[$this->fuel->auth->get_session_namespace()][$this->_get_csrf_token_name()] : NULL; } // -------------------------------------------------------------------- /** - * Validates a submission based on the CSRF tokent + * Validates a submission based on the CSRF token * * @access protected * @return void */ protected function _is_valid_csrf() { - return !empty($_SESSION[$this->_get_csrf_token_name()]) AND $_SESSION[$this->_get_csrf_token_name()] == $this->input->post($this->_get_csrf_token_name()); + return !empty($this->_session_csrf()) AND $this->_session_csrf() === $this->input->post($this->_get_csrf_token_name()); } } From 133e51dd380d2800628d0af0c58365795059026a Mon Sep 17 00:00:00 2001 From: David McReynolds Date: Wed, 29 Jan 2020 12:50:47 -0800 Subject: [PATCH 2/2] fix: version bump to 1.4.6 --- fuel/modules/fuel/config/fuel_constants.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fuel/modules/fuel/config/fuel_constants.php b/fuel/modules/fuel/config/fuel_constants.php index 413854c69..9fc9f4969 100644 --- a/fuel/modules/fuel/config/fuel_constants.php +++ b/fuel/modules/fuel/config/fuel_constants.php @@ -1,6 +1,6 @@