FetchMetadataGuard implements MiddlewareInterface
Read onlyYes
Rejects state-changing backend requests which were not initiated by the backend itself.
Browsers describe the origin of a request in the Sec-Fetch-Site header (or Origin
for older ones), which cannot be forged by a web page. Requests to anonymous routes,
such as webhooks or the login, are not restricted, neither are safe methods like GET.
Depends on the NormalizedParams and the backend routing middleware.
Table of Contents
Interfaces
- MiddlewareInterface
Methods
- __construct() : mixed
- process() : ResponseInterface
Methods
__construct()
public
__construct(Features $features) : mixed
Parameters
- $features : Features
process()
public
process(ServerRequestInterface $request, RequestHandlerInterface $handler) : ResponseInterface
Parameters
- $request : ServerRequestInterface
- $handler : RequestHandlerInterface