Skip to content

Commit e6a8ebb

Browse files
authored
Make CSRF tokens better named (#1131)
1 parent 5aec5d8 commit e6a8ebb

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

42 files changed

+72
-72
lines changed

src/Controller/Admin/AdminMagazineOwnershipRequestController.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ public function requests(Request $request): Response
3232
#[IsGranted('ROLE_ADMIN')]
3333
public function accept(Magazine $magazine, User $user, Request $request): Response
3434
{
35-
$this->validateCsrf('admin_magazine_ownership_requests_accept', $request->request->get('token'));
35+
$this->validateCsrf('admin_magazine_ownership_requests_accept', $request->getPayload()->get('token'));
3636

3737
$this->manager->acceptOwnershipRequest($magazine, $user, $this->getUserOrThrow());
3838

@@ -42,7 +42,7 @@ public function accept(Magazine $magazine, User $user, Request $request): Respon
4242
#[IsGranted('ROLE_ADMIN')]
4343
public function reject(Magazine $magazine, User $user, Request $request): Response
4444
{
45-
$this->validateCsrf('admin_magazine_ownership_requests_reject', $request->request->get('token'));
45+
$this->validateCsrf('admin_magazine_ownership_requests_reject', $request->getPayload()->get('token'));
4646

4747
$this->manager->toggleOwnershipRequest($magazine, $user);
4848

src/Controller/Admin/AdminModeratorController.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ public function moderators(Request $request): Response
4949
#[IsGranted('ROLE_ADMIN')]
5050
public function removeModerator(User $user, Request $request): Response
5151
{
52-
$this->validateCsrf('remove_moderator', $request->request->get('token'));
52+
$this->validateCsrf('remove_moderator', $request->getPayload()->get('token'));
5353

5454
$this->manager->removeModerator($user);
5555

src/Controller/BoostController.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ public function __construct(
2323
#[IsGranted('ROLE_USER')]
2424
public function __invoke(VotableInterface $subject, Request $request): Response
2525
{
26-
$this->validateCsrf('boost', $request->request->get('token'));
26+
$this->validateCsrf('boost', $request->getPayload()->get('token'));
2727

2828
$this->manager->vote(VotableInterface::VOTE_UP, $subject, $this->getUserOrThrow());
2929

src/Controller/Domain/DomainBlockController.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ public function __construct(
2222
#[IsGranted('ROLE_USER')]
2323
public function block(Domain $domain, Request $request): Response
2424
{
25-
$this->validateCsrf('block', $request->request->get('token'));
25+
$this->validateCsrf('block', $request->getPayload()->get('token'));
2626

2727
$this->manager->block($domain, $this->getUserOrThrow());
2828

@@ -36,7 +36,7 @@ public function block(Domain $domain, Request $request): Response
3636
#[IsGranted('ROLE_USER')]
3737
public function unblock(Domain $domain, Request $request): Response
3838
{
39-
$this->validateCsrf('block', $request->request->get('token'));
39+
$this->validateCsrf('block', $request->getPayload()->get('token'));
4040

4141
$this->manager->unblock($domain, $this->getUserOrThrow());
4242

src/Controller/Domain/DomainSubController.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ public function __construct(
2222
#[IsGranted('ROLE_USER')]
2323
public function subscribe(Domain $domain, Request $request): Response
2424
{
25-
$this->validateCsrf('subscribe', $request->request->get('token'));
25+
$this->validateCsrf('subscribe', $request->getPayload()->get('token'));
2626

2727
$this->manager->subscribe($domain, $this->getUserOrThrow());
2828

@@ -36,7 +36,7 @@ public function subscribe(Domain $domain, Request $request): Response
3636
#[IsGranted('ROLE_USER')]
3737
public function unsubscribe(Domain $domain, Request $request): Response
3838
{
39-
$this->validateCsrf('subscribe', $request->request->get('token'));
39+
$this->validateCsrf('subscribe', $request->getPayload()->get('token'));
4040

4141
$this->manager->unsubscribe($domain, $this->getUserOrThrow());
4242

src/Controller/Entry/Comment/EntryCommentChangeAdultController.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ public function __invoke(
3131
EntryComment $comment,
3232
Request $request
3333
): Response {
34-
$this->validateCsrf('change_adult', $request->request->get('token'));
34+
$this->validateCsrf('change_adult', $request->getPayload()->get('token'));
3535

3636
$comment->isAdult = 'on' === $request->get('adult');
3737

src/Controller/Entry/Comment/EntryCommentDeleteController.php

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ public function delete(
3232
EntryComment $comment,
3333
Request $request
3434
): Response {
35-
$this->validateCsrf('entry_comment_delete', $request->request->get('token'));
35+
$this->validateCsrf('entry_comment_delete', $request->getPayload()->get('token'));
3636

3737
$this->manager->delete($this->getUserOrThrow(), $comment);
3838

@@ -50,7 +50,7 @@ public function restore(
5050
EntryComment $comment,
5151
Request $request
5252
): Response {
53-
$this->validateCsrf('entry_comment_restore', $request->request->get('token'));
53+
$this->validateCsrf('entry_comment_restore', $request->getPayload()->get('token'));
5454

5555
$this->manager->restore($this->getUserOrThrow(), $comment);
5656

@@ -68,7 +68,7 @@ public function purge(
6868
EntryComment $comment,
6969
Request $request
7070
): Response {
71-
$this->validateCsrf('entry_comment_purge', $request->request->get('token'));
71+
$this->validateCsrf('entry_comment_purge', $request->getPayload()->get('token'));
7272

7373
$this->manager->purge($this->getUserOrThrow(), $comment);
7474

src/Controller/Entry/EntryChangeAdultController.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ public function __invoke(
2828
Entry $entry,
2929
Request $request
3030
): Response {
31-
$this->validateCsrf('change_adult', $request->request->get('token'));
31+
$this->validateCsrf('change_adult', $request->getPayload()->get('token'));
3232

3333
$entry->isAdult = 'on' === $request->get('adult');
3434

src/Controller/Entry/EntryChangeMagazineController.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ public function __invoke(
3030
Entry $entry,
3131
Request $request
3232
): Response {
33-
$this->validateCsrf('change_magazine', $request->request->get('token'));
33+
$this->validateCsrf('change_magazine', $request->getPayload()->get('token'));
3434

3535
$newMagazine = $this->repository->findOneByName($request->get('change_magazine')['new_magazine']);
3636

src/Controller/Entry/EntryDeleteController.php

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ public function delete(
2929
Entry $entry,
3030
Request $request
3131
): Response {
32-
$this->validateCsrf('entry_delete', $request->request->get('token'));
32+
$this->validateCsrf('entry_delete', $request->getPayload()->get('token'));
3333

3434
$this->manager->delete($this->getUserOrThrow(), $entry);
3535

@@ -50,7 +50,7 @@ public function restore(
5050
Entry $entry,
5151
Request $request
5252
): Response {
53-
$this->validateCsrf('entry_restore', $request->request->get('token'));
53+
$this->validateCsrf('entry_restore', $request->getPayload()->get('token'));
5454

5555
$this->manager->restore($this->getUserOrThrow(), $entry);
5656

@@ -66,7 +66,7 @@ public function purge(
6666
Entry $entry,
6767
Request $request
6868
): Response {
69-
$this->validateCsrf('entry_purge', $request->request->get('token'));
69+
$this->validateCsrf('entry_purge', $request->getPayload()->get('token'));
7070

7171
$this->manager->purge($this->getUserOrThrow(), $entry);
7272

0 commit comments

Comments
 (0)