We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents 71a33e6 + 5316560 commit d5f5c2eCopy full SHA for d5f5c2e
lib/internal/Magento/Framework/Data/Form/FormKey/Validator.php
@@ -5,6 +5,8 @@
5
*/
6
namespace Magento\Framework\Data\Form\FormKey;
7
8
+use Magento\Framework\Encryption\Helper\Security;
9
+
10
/**
11
* @api
12
@@ -32,9 +34,7 @@ public function __construct(\Magento\Framework\Data\Form\FormKey $formKey)
32
34
public function validate(\Magento\Framework\App\RequestInterface $request)
33
35
{
36
$formKey = $request->getParam('form_key', null);
- if (!$formKey || $formKey !== $this->_formKey->getFormKey()) {
- return false;
37
- }
38
- return true;
+ return $formKey && Security::compareStrings($formKey, $this->_formKey->getFormKey());
39
}
40
0 commit comments