Welcome Guest, Not a member yet? Register   Sign In
CSRF temporary deactivation
#1

[eluser]Treeda[/eluser]
Hi there...

i think everyone working with CI 2+ and CSRF enabled might stumbled over the problem that users without cookies are not able to send any forms.

Well, for the internal part, after a login, where users have to support cookies this isn't a problem, but on the front side, i would like to allow users to use a send message form etc, but if they have cookies disabled this is not possible.

Is there a recommended way of temporary deactivate CSRF protection? Let's say in the constructor of a controller?
Unfortunatly it seems that the security class is fetched very very early and you have no chance to do anything inside a controller....

I would aprpeciate any help

Thanks
Treeda


Messages In This Thread
CSRF temporary deactivation - by El Forum - 08-02-2011, 11:23 AM
CSRF temporary deactivation - by El Forum - 08-03-2011, 12:18 PM
CSRF temporary deactivation - by El Forum - 08-04-2011, 10:30 AM



Theme © iAndrew 2016 - Forum software by © MyBB