We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 92044eb commit 727503dCopy full SHA for 727503d
lib/internal/Magento/Framework/Data/Form/FormKey/Validator.php
@@ -5,6 +5,11 @@
5
*/
6
namespace Magento\Framework\Data\Form\FormKey;
7
8
+use Magento\Framework\Encryption\Helper\Security;
9
+
10
+/**
11
+ * @api
12
+ */
13
class Validator
14
{
15
/**
@@ -29,9 +34,11 @@ public function __construct(\Magento\Framework\Data\Form\FormKey $formKey)
29
34
public function validate(\Magento\Framework\App\RequestInterface $request)
30
35
31
36
$formKey = $request->getParam('form_key', null);
32
- if (!$formKey || $formKey !== $this->_formKey->getFormKey()) {
37
38
+ if (!$formKey) {
33
39
return false;
40
}
- return true;
41
42
+ return Security::compareStrings($formKey, $this->_formKey->getFormKey());
43
44
0 commit comments