Commit c31e113d by Qiang Xue

Fixes #1671

parent 4b569f3e
...@@ -1121,7 +1121,7 @@ class Request extends \yii\base\Request ...@@ -1121,7 +1121,7 @@ class Request extends \yii\base\Request
private function validateCsrfTokenInternal($token, $trueToken) private function validateCsrfTokenInternal($token, $trueToken)
{ {
$token = str_replace('.', '+', base64_decode($token)); $token = base64_decode(str_replace('.', '+', $token));
$n = StringHelper::byteLength($token); $n = StringHelper::byteLength($token);
if ($n <= self::CSRF_MASK_LENGTH) { if ($n <= self::CSRF_MASK_LENGTH) {
return false; return false;
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment