CsrfMiddleware.php 779 B

12345678910111213141516171819202122232425262728293031323334353637
  1. <?php namespace App\Http\Middleware;
  2. use Closure;
  3. use Illuminate\Contracts\Routing\Middleware;
  4. use Illuminate\Session\TokenMismatchException;
  5. class CsrfMiddleware implements Middleware {
  6. /**
  7. * Handle an incoming request.
  8. *
  9. * @param \Illuminate\Http\Request $request
  10. * @param \Closure $next
  11. * @return mixed
  12. */
  13. public function handle($request, Closure $next)
  14. {
  15. if ($request->method() == 'GET' || $this->tokensMatch($request))
  16. {
  17. return $next($request);
  18. }
  19. throw new TokenMismatchException;
  20. }
  21. /**
  22. * Determine if the session and input CSRF tokens match.
  23. *
  24. * @param \Illuminate\Http\Request $request
  25. * @return bool
  26. */
  27. protected function tokensMatch($request)
  28. {
  29. return $request->session()->token() == $request->input('_token');
  30. }
  31. }