move cookie payload check into cookie class.
This commit is contained in:
parent
c847bc4d5e
commit
071d8ab069
|
@ -45,9 +45,9 @@ public static function get($name, $default = null)
|
||||||
// character for convenience. To separate the hash and the contents
|
// character for convenience. To separate the hash and the contents
|
||||||
// we can simply expode on that character.
|
// we can simply expode on that character.
|
||||||
//
|
//
|
||||||
// By re-feeding the cookie value into the "sign" method, we should
|
// By re-feeding the cookie value into the "sign" method we should
|
||||||
// be able to generate a hash that matches the one taken out of the
|
// be able to generate a hash that matches the one taken from the
|
||||||
// cookie. If they don't match, the cookie value has been changed.
|
// cookie. If they don't, the cookie value has been changed.
|
||||||
list($hash, $value) = explode('~', $value, 2);
|
list($hash, $value) = explode('~', $value, 2);
|
||||||
|
|
||||||
if (static::hash($name, $value) === $hash)
|
if (static::hash($name, $value) === $hash)
|
||||||
|
@ -88,6 +88,15 @@ public static function put($name, $value, $minutes = 0, $path = '/', $domain = n
|
||||||
|
|
||||||
$_COOKIE[$name] = static::sign($name, $value);
|
$_COOKIE[$name] = static::sign($name, $value);
|
||||||
|
|
||||||
|
// A cookie payload can't exceed 4096 bytes, so if the payload
|
||||||
|
// is greater than that, we'll raise an exception to warn the
|
||||||
|
// developer of the problem since it may cause problems with
|
||||||
|
// the application, especially if using cookie sessions.
|
||||||
|
if (strlen($_COOKIE[$name]) > 4000)
|
||||||
|
{
|
||||||
|
throw new \Exception("Payload too large for cookie.");
|
||||||
|
}
|
||||||
|
|
||||||
return setcookie($name, $_COOKIE[$name], $time, $path, $domain, $secure);
|
return setcookie($name, $_COOKIE[$name], $time, $path, $domain, $secure);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
@ -41,14 +41,6 @@ public function save($session, $config, $exists)
|
||||||
|
|
||||||
$payload = Crypter::encrypt(serialize($session));
|
$payload = Crypter::encrypt(serialize($session));
|
||||||
|
|
||||||
// A cookie payload can't exceed 4096 bytes, so if the encrypted payload
|
|
||||||
// is greater than that, we'll throw an exception so the developer can
|
|
||||||
// switch to another session driver for the application.
|
|
||||||
if (strlen($payload) > 4000)
|
|
||||||
{
|
|
||||||
throw new \Exception("Session payload too large for cookie.");
|
|
||||||
}
|
|
||||||
|
|
||||||
\Laravel\Cookie::put(Cookie::payload, $payload, $lifetime, $path, $domain);
|
\Laravel\Cookie::put(Cookie::payload, $payload, $lifetime, $path, $domain);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue