File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -144,14 +144,14 @@ return [
144144In case Yii framework is used along with config plugin, the package is [ configured] ( ./config/di-web.php )
145145automatically to use synchronizer token and masked decorator. You can change that depending on your needs.
146146
147- Use synchronizer token for sensitive anonymous forms or tokens that must be one-time or revocable; use HMAC token for
148- authenticated-only forms when a short token replay window is acceptable .
147+ Use synchronizer token for sensitive anonymous forms; use HMAC token for authenticated-only forms when a submitted
148+ token may stay valid for a few minutes .
149149
150150``` mermaid
151151flowchart TD
152152 A{Anonymous forms to protect?}
153153 A -- Yes --> S[Synchronizer]
154- A -- No --> B{Need one-time or revocable tokens ?}
154+ A -- No --> B{Old or repeated submits must fail ?}
155155 B -- Yes --> S
156156 B -- No --> C{Per-environment secret key?}
157157 C -- No --> S
You can’t perform that action at this time.
0 commit comments