FetchMetadataGuard implements MiddlewareInterface

Read onlyYes

Rejects state-changing backend requests which were not initiated by the backend itself.

Browsers describe the origin of a request in the Sec-Fetch-Site header (or Origin for older ones), which cannot be forged by a web page. Requests to anonymous routes, such as webhooks or the login, are not restricted, neither are safe methods like GET.

Depends on the NormalizedParams and the backend routing middleware.

Internal

Table of Contents

Interfaces

MiddlewareInterface

Methods

__construct()  : mixed
process()  : ResponseInterface

Methods

process()

public process(ServerRequestInterface $request, RequestHandlerInterface $handler) : ResponseInterface
Parameters
$request : ServerRequestInterface
$handler : RequestHandlerInterface
Return values
ResponseInterface
On this page

Search results