From 466d9106fcfea8fcdb21fc41e7ec5c69f40045df Mon Sep 17 00:00:00 2001 From: "Mr.Chung" <39075420+zhongshaofa@users.noreply.github.com> Date: Thu, 16 Sep 2021 12:52:10 +0800 Subject: [PATCH] =?UTF-8?q?[fix]=E4=BF=AE=E5=A4=8D=E5=BD=93=E5=9F=9F?= =?UTF-8?q?=E5=90=8D=E5=B8=A6=E6=9C=89=E7=AB=AF=E5=8F=A3=E6=97=B6=EF=BC=8C?= =?UTF-8?q?REFERER=E9=AA=8C=E8=AF=81=E5=A4=B1=E8=B4=A5=E7=9A=84=E9=97=AE?= =?UTF-8?q?=E9=A2=98?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- app/admin/middleware/CsrfMiddleware.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/admin/middleware/CsrfMiddleware.php b/app/admin/middleware/CsrfMiddleware.php index 6ba1aed4..b61d4ee6 100644 --- a/app/admin/middleware/CsrfMiddleware.php +++ b/app/admin/middleware/CsrfMiddleware.php @@ -31,7 +31,7 @@ public function handle(Request $request, \Closure $next) // 跨域校验 $refererUrl = $request->header('REFERER', null); $refererInfo = parse_url($refererUrl); - $host = $request->host(); + $host = $request->host(true); if (!isset($refererInfo['host']) || $refererInfo['host'] != $host) { $this->error('当前请求不合法!'); } @@ -50,4 +50,4 @@ public function handle(Request $request, \Closure $next) } return $next($request); } -} \ No newline at end of file +}