erreur CodeIgniter CSRF: "l'action que vous avez demandée n'est pas autorisée."
j'ai activé l'option csrf_protection dans le fichier de configuration du codeigniter, et j'ai utilisé la fonction form_open () pour créer mes formulaires. mais lorsque je soumets le formulaire, cette erreur se produit:
The action you have requested is not allowed.
j'ai fait les réponses comme ceci (taht est le plus lié à ma question): question
mais ils n'ont pas fonctionné et le problème persiste. config.php
<?php if ( ! defined('BASEPATH')) exit('No direct script access allowed');
| Base Site URL
| URL to your CodeIgniter root. Typically this will be your base URL,
| WITH a trailing slash:
| If this is not set then CodeIgniter will guess the protocol, domain and
| path to your installation.
$config['base_url'] = '';
| Index File
| Typically this will be your index.php file, unless you've renamed it to
| something else. If you are using mod_rewrite to remove the page set this
| variable so that it is blank.
$config['index_page'] = 'index.php';
| This item determines which server global should be used to retrieve the
| URI string. The default setting of 'AUTO' works for most servers.
| If your links do not seem to work, try one of the other delicious flavors:
| 'AUTO' Default - auto detects
$config['uri_protocol'] = 'AUTO';
| URL suffix
| This option allows you to add a suffix to all URLs generated by CodeIgniter.
| For more information please see the user guide:
$config['url_suffix'] = '';
| Default Language
| This determines which set of language files should be used. Make sure
| there is an available translation if you intend to use something other
| than english.
$config['language'] = 'persian';
| Default Character Set
| This determines which character set is used by default in various methods
| that require a character set to be provided.
$config['charset'] = 'UTF-8';
| Enable/Disable System Hooks
| If you would like to use the 'hooks' feature you must enable it by
| setting this variable to TRUE (boolean). See the user guide for details.
$config['enable_hooks'] = FALSE;
| Class Extension Prefix
| This item allows you to set the filename/classname prefix when extending
| native libraries. For more information please see the user guide:
$config['subclass_prefix'] = 'MY_';
| Allowed URL Characters
| This lets you specify with a regular expression which characters are permitted
| within your URLs. When someone tries to submit a URL with disallowed
| characters they will get a warning message.
| As a security measure you are STRONGLY encouraged to restrict URLs to
| as few characters as possible. By default only these are allowed: a-z 0-9~%.:_-
| Leave blank to allow all characters -- but only if you are insane.
$config['permitted_uri_chars'] = 'a-z 0-9~%.:_-';
| Enable Query Strings
| By default CodeIgniter uses search-engine friendly segment based URLs:
| By default CodeIgniter enables access to the $_GET array. If for some
| reason you would like to disable it, set 'allow_get_array' to FALSE.
| You can optionally enable standard query string based URLs:
| Options are: TRUE or FALSE (boolean)
| The other items let you set the query string 'words' that will
| invoke your controllers and its functions:
| Please note that some of the helpers won't work as expected when
| this feature is enabled, since CodeIgniter is designed primarily to
| use segment based URLs.
$config['allow_get_array'] = TRUE;
$config['enable_query_strings'] = FALSE;
$config['controller_trigger'] = 'c';
$config['function_trigger'] = 'm';
$config['directory_trigger'] = 'd'; // experimental not currently in use
| Error Logging Threshold
| If you have enabled error logging, you can set an error threshold to
| determine what gets logged. Threshold options are:
| You can enable error logging by setting a threshold over zero. The
| threshold determines what gets logged. Threshold options are:
| 0 = Disables logging, Error logging TURNED OFF
| 1 = Error Messages (including PHP errors)
| 2 = Debug Messages
| 3 = Informational Messages
| 4 = All Messages
| For a live site you'll usually only enable Errors (1) to be logged otherwise
| your log files will fill up very fast.
$config['log_threshold'] = 0;
| Error Logging Directory Path
| Leave this BLANK unless you would like to set something other than the default
| application/logs/ folder. Use a full server path with trailing slash.
$config['log_path'] = '';
| Date Format for Logs
| Each item that is logged has an associated date. You can use PHP date
| codes to set your own date formatting
$config['log_date_format'] = 'Y-m-d H:i:s';
| Cache Directory Path
| Leave this BLANK unless you would like to set something other than the default
| system/cache/ folder. Use a full server path with trailing slash.
$config['cache_path'] = '';
| Encryption Key
| If you use the Encryption class or the Session class you
| MUST set an encryption key. See the user guide for info.
$config['encryption_key'] = 'b{{h#/Ib;pd<%+H0?ujvv9KLRc0LR-o8ot"K*so.J&}4qCQ+Ij81ihd48fx5_';
| Session Variables
| 'sess_cookie_name' = the name you want for the cookie
| 'sess_expiration' = the number of SECONDS you want the session to last.
| by default sessions last 7200 seconds (two hours). Set to zero for no expiration.
| 'sess_expire_on_close' = Whether to cause the session to expire automatically
| when the browser window is closed
| 'sess_encrypt_cookie' = Whether to encrypt the cookie
| 'sess_use_database' = Whether to save the session data to a database
| 'sess_table_name' = The name of the session database table
| 'sess_match_ip' = Whether to match the user's IP address when reading the session data
| 'sess_match_useragent' = Whether to match the User Agent when reading the session data
| 'sess_time_to_update' = how many seconds between CI refreshing Session Information
$config['sess_cookie_name'] = 'ins_mngm_system';
$config['sess_expiration'] = 7200;
$config['sess_expire_on_close'] = TRUE;
$config['sess_encrypt_cookie'] = TRUE;
$config['sess_use_database'] = TRUE;
$config['sess_table_name'] = 'user_sessions';
$config['sess_match_ip'] = TRUE;
$config['sess_match_useragent'] = TRUE;
$config['sess_time_to_update'] = 300;
| Cookie Related Variables
| 'cookie_prefix' = Set a prefix if you need to avoid collisions
| 'cookie_domain' = Set to for site-wide cookies
| 'cookie_path' = Typically will be a forward slash
| 'cookie_secure' = Cookies will only be set if a secure HTTPS connection exists.
$config['cookie_prefix'] = "";
$config['cookie_domain'] = "";
$config['cookie_path'] = "/";
$config['cookie_secure'] = TRUE;
| Global XSS Filtering
| Determines whether the XSS filter is always active when GET, POST or
| COOKIE data is encountered
$config['global_xss_filtering'] = TRUE;
| Cross Site Request Forgery
| Enables a CSRF cookie token to be set. When set to TRUE, token will be
| checked on a submitted form. If you are accepting user data, it is strongly
| recommended CSRF protection be enabled.
| 'csrf_token_name' = The token name
| 'csrf_cookie_name' = The cookie name
| 'csrf_expire' = The number in seconds the token should expire.
$config['csrf_protection'] = TRUE;
$config['csrf_token_name'] = 'relt';
$config['csrf_cookie_name'] = 'csrf_cookie_name';
$config['csrf_expire'] = 7200;
| Output Compression
| Enables Gzip output compression for faster page loads. When enabled,
| the output class will test whether your server supports Gzip.
| Even if it does, however, not all browsers support compression
| so enable only if you are reasonably sure your visitors can handle it.
| VERY IMPORTANT: If you are getting a blank page when compression is enabled it
| means you are prematurely outputting something to your browser. It could
| even be a line of whitespace at the end of one of your scripts. For
| compression to work, nothing can be sent before the output buffer is called
| by the output class. Do not 'echo' any values with compression enabled.
$config['compress_output'] = FALSE;
| Master Time Reference
| Options are 'local' or 'gmt'. This pref tells the system whether to use
| your server's local time as the master 'now' reference, or convert it to
| GMT. See the 'date helper' page of the user guide for information
| regarding date handling.
$config['time_reference'] = 'local';
| Rewrite PHP Short Tags
| If your PHP installation does not have short tag support enabled CI
| can rewrite the tags on-the-fly, enabling you to utilize that syntax
| in your view files. Options are TRUE or FALSE (boolean)
$config['rewrite_short_tags'] = FALSE;
| Reverse Proxy IPs
| If your server is behind a reverse proxy, you must whitelist the proxy IP
| addresses from which CodeIgniter should trust the HTTP_X_FORWARDED_FOR
| header in order to properly identify the visitor's IP address.
| Comma-delimited, e.g. ','
$config['proxy_ips'] = '';
/* End of file config.php */
/* Location: ./application/config/config.php */
contrôleur principal.php):
<?php if ( ! defined('BASEPATH')) exit('No direct script access allowed');
class Main extends CI_Controller {
//public function __construct()
// $this->load->controller('access_controll');
public function index()
public function login()
public function registration()
public function forgot()
/* End of file main.php */
/* Location: ./application/controllers/main.php */
voir (connexion.php):
<!DOCTYPE html>
<html lang="en">
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta name="description" content="">
<meta name="author" content="">
<link rel="shortcut icon" href="<?php echo base_url();?>template/img/favicon.png">
<title>ورود به حساب کاربری</title>
<!-- Bootstrap core CSS -->
<link href="<?php echo base_url();?>template/css/bootstrap.rtl.css" rel="stylesheet">
<!-- Custom styles for this template -->
<link href="<?php echo base_url();?>template/style.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="js/html5shiv.js"></script>
<script src="js/respond.min.js"></script>
<body id="login">
<div class="login-content">
<div class="widget-content">
<h1>سامانه مدیریت مشتریان</h1>
<div class="alert alert-danger"><?php echo $message;?></div>
<?php echo form_open('auth/login', array('role'=>'form')); ?>
<div class="form-group">
<label for="identity">شناسه کاربری:</label>
<div class="input-group"> <span class="input-group-addon"><i class="glyphicon glyphicon-user"></i></span>
<?php echo form_input(array('name'=>'identity', 'type'=>'text', 'placeholder'=>'نام کاربری یا ایمیل', 'class'=>'form-control', 'id'=>'identity')); ?>
<div class="form-group">
<label for="pass">گذرواژه:</label>
<div class="input-group"> <span class="input-group-addon"><i class="glyphicon glyphicon-lock"></i></span>
<?php echo form_input(array('name'=>'pass', 'type'=>'password', 'placeholder'=>'گذرواژه', 'class'=>'form-control')); ?>
<div class="checkbox">
<div class="col-sm-offset-1 col-sm-12">
<?php echo form_checkbox(array('name'=>'remember', 'value'=>1, 'type'=>'checkbox')); ?>
مرا به خاطر بسپار </label>
<div class="form-group">
<div class="col-sm-offset-1 col-sm-12">
<input type="submit" class="btn btn-default" value="ورود" />
<?php echo form_close(); ?>
<div class="forgot">
<ul class="list-unstyled">
<li> <i class="glyphicon glyphicon-chevron-left"></i> <a href="<?php echo site_url("main/registration");?>">ایجاد حساب کاربری جدید</a> </li>
<li> <i class="glyphicon glyphicon-chevron-left"></i> <a href="<?php echo site_url("main/forgot");?>">رمز عبور خود را فراموش کرده اید؟</a> </li>
<!-- /.container -->
<!-- Bootstrap core JavaScript
================================================== -->
<!-- Placed at the end of the document so the pages load faster -->
<script src="js/jquery.js"></script>
<script src="js/bootstrap.rtl.min.js"></script>
12 réponses
Le Problème résolu par cette Solution:
dans le fichier de configuration à FALSE si vous utilisez HTTP.
Le plus facile pour moi était de whitelist L'URI comme expliqué dans le guide de L'utilisateur CodeIgniter (ici)
URIs Select peut être whitelisted à partir de la protection csrf (par exemple API paramètres attending exteriorly POSTed content). Vous pouvez ajouter ces Uri en éditant le paramètre de configuration "csrf_exclude_uris":
$config['csrf_exclude_uris'] = array('api/person/add');
il suffit d'Inclure dans votre formulaire et tout ira bien ensuite.
<input type="hidden" name="<?php echo $this->security->get_csrf_token_name();?>" value="<?php echo $this->security->get_csrf_hash();?>">
dans config / config.php j'ai
$config['csrf_token_name'] = '';
mais quand j'utilise var_dump pour $_POST je vois:
["my_token_name"]=> string(32) "f5d78f8c8bb1800d10af59df8c302515"
IC changer mon csrf_token_name (sic!)
la Solution: J'ai changé
$config['csrf_token_name'] = '';
$config['csrf_token_name'] = 'my_token_name';
maintenant ça marche.
quand tout le reste a échoué, j'ai remarqué que j'avais mes variables cookie définies, supprimant le nom du cookie, etc. résolu mon problème.
à tous ceux qui ont essayé tout ce qui a été suggéré ici, et qui ont encore ce problème.
mon problème était la date d'expiration du cookie.
$config['csrf_expire'] = 7200;
après que le cookie expire et que l'utilisateur essaie de soumettre un formulaire, il obtiendra l'erreur
The action you have requested is not allowed.
j'ai ajouté un javascript simple à chaque page, ce qui corrige le problème pour 99% de vos utilisateurs. (les 1% étant des utilisateurs qui ont désactivé JS dans leur navigateur)
setInterval(function () {
if(alert('Your session has expired!')){}
else window.location.reload();
}, 7200000);
dans la configuration si vous avez défini le nom de domaine du cookie
$config['cookie_domain'] = '';
et vous parcourez en utilisant localhost. vous recevrez le message d'erreur
L'action que vous avez demandée n'est pas autorisée
vérifier que si une aide
assurez-vous que votre BASE_URL
correspond à l'URL que vous visualisez. J'ai deux alias (un a été créé pour oauth) et le projet fonctionne sur les deux alias, mais CSRF échouera si le BASE_URL
ne correspond pas à l'URL du navigateur.
si vous vous permettez de vrai dans $config['csrf_protection'] = true;
dans le fichier de configuration et vous aussi ajouter autoload
formulaire que nous pouvons utiliser.
Étape 1. dans le dossier de configuration, le fichier autoload aide à télécharger le formulaire
$autoload['helper'] = array('url', 'file','form');
Étape 2.
$config['csrf_protection'] = true;
Étape 3. pendant le téléchargement dans le dossier de vue
<?php echo form_open_multipart('admin/file_upload'); ?>
sinon, vous ne pouvez utiliser que
$config['csrf_protection'] = false;
changer la ligne 451
$config['csrf_protection'] = true;
$config['csrf_protection'] = false;
parce que cela csrf_protection
est déprécié dans CodeIgniter
$config['csrf_exclude_uris'] = array('main/registration','main/login');
j'ai trouvé une solution à ce problème qui est très simple. J'ai supprimé le div avec le style display:none entourant l'entrée csrf_protection. Le div n'est pas pertinent puisque le type d'entrée est défini à hidden. Dans CodeIginiterFolder/system/helpers / form_helper.php, j'ai changé le contenu suivant (autour de la ligne 75) :
if (is_array($hidden) AND count($hidden) > 0)
$form .= sprintf("<div style=\"display:none\">%s</div>", form_hidden($hidden));
pour le suivant :
if (is_array($hidden) AND count($hidden) > 0)
$form .= form_hidden($hidden);