From c3e3d9dc4b8a4f6f52f1f89233f2a1d19011fc24 Mon Sep 17 00:00:00 2001 From: Taylor Otwell Date: Mon, 26 Jan 2015 19:32:22 -0600 Subject: [PATCH] Include CSRF middleware in base install for easy override / whitelist. This makes it easy to skip CSRF verification for things like web hooks and such from GitHub / Stripe. --- app/Http/Kernel.php | 2 +- app/Http/Middleware/VerifyCsrfToken.php | 20 ++++++++++++++++++++ 2 files changed, 21 insertions(+), 1 deletion(-) create mode 100644 app/Http/Middleware/VerifyCsrfToken.php diff --git a/app/Http/Kernel.php b/app/Http/Kernel.php index 0bae39f2..0a2addca 100644 --- a/app/Http/Kernel.php +++ b/app/Http/Kernel.php @@ -15,7 +15,7 @@ class Kernel extends HttpKernel { 'Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse', 'Illuminate\Session\Middleware\StartSession', 'Illuminate\View\Middleware\ShareErrorsFromSession', - 'Illuminate\Foundation\Http\Middleware\VerifyCsrfToken', + 'App\Http\Middleware\VerifyCsrfToken', ]; /** diff --git a/app/Http/Middleware/VerifyCsrfToken.php b/app/Http/Middleware/VerifyCsrfToken.php new file mode 100644 index 00000000..750a39b1 --- /dev/null +++ b/app/Http/Middleware/VerifyCsrfToken.php @@ -0,0 +1,20 @@ +