檢查 POST 檔案來源是否為本 HOST 內的網頁 防止 CSRF 和 XSS
if( isset($_SERVER['HTTP_REFERER']) ) { if( strstr(strtolower(@$_SERVER['HTTP_REFERER']), $_SERVER['HTTP_HOST'])==false ) { header("HTTP/1.1 400 Bad Request"); echo 'HTTP/1.1 400 Bad Request'; exit(); } }
檢查 POST 檔案來源是否為本 HOST 內的網頁 防止 CSRF 和 XSS
if( isset($_SERVER['HTTP_REFERER']) ) { if( strstr(strtolower(@$_SERVER['HTTP_REFERER']), $_SERVER['HTTP_HOST'])==false ) { header("HTTP/1.1 400 Bad Request"); echo 'HTTP/1.1 400 Bad Request'; exit(); } }