Welcome to FrostSW!

FrostMVC PHP Framework

Documentation   |   Version

Security

FrostMVC\Security

use FrostMVC\Security;

Security utilities: password hashing, CSRF token management, AES-256-GCM encryption, and basic file upload content scanning.

Properties

PropertyTypeDescription
Security::$CSRFTokenConfig mixed

Methods

->__construct() —
->checkCSRFToken()

Validates the CSRF token on every incoming POST request. On failure, responds based on the submission context: - XHR forms: JSON error response - Inline forms: sets a flash error message - Standard forms: renders the error page with 403 When no POST data is present, a new token is generated for the next request.

->decrypt()

Decrypts a string produced by encrypt(). Verifies the HMAC-SHA256 before returning the plaintext. Returns an empty string on tampered or malformed input.

->encrypt()

Encrypts a string using AES-256-GCM. The output is formatted as: base64(IV + HMAC-SHA256 + ciphertext), prefixed by the GCM authentication tag, separated by ':::'.

::fileScan()

Scans an uploaded file's raw contents for common PHP webshell signatures. Optionally deletes the file immediately when a threat is detected. This is a basic heuristic check and not a substitute for a full AV scan.

->getCSRFToken()

Returns the current CSRF token object, generating one if necessary.

->isCSRFExcluded()

Returns true when the current URL is in the CSRF exclusion list or when CSRF protection is globally disabled.

::pass()

Hashes a password using the strongest available algorithm (Argon2id, Argon2i, or bcrypt). The cost factor is auto-calibrated so that hashing takes at least $timeTarget seconds, ensuring an appropriate work factor regardless of hardware speed.

->setCSRFToken()

Generates a new CSRF token, stores it in a cookie, and caches it statically. When $CSRFTokenConfig['regenerate'] is false and a valid cookie already exists, the existing token is reused.

->verifyCSRFToken()

Validates a submitted CSRF token against the stored cookie value. Regenerates the token after a successful POST verification when configured to do so.

__construct()

$security->__construct()

No description yet.

checkCSRFToken()

$security->checkCSRFToken()

Validates the CSRF token on every incoming POST request. On failure, responds based on the submission context: - XHR forms: JSON error response - Inline forms: sets a flash error message - Standard forms: renders the error page with 403 When no POST data is present, a new token is generated for the next request.

decrypt()

$security->decrypt($string, $key = '0', $cipher = 'aes-256-gcm', $options = OPENSSL_RAW_DATA)

Decrypts a string produced by encrypt(). Verifies the HMAC-SHA256 before returning the plaintext. Returns an empty string on tampered or malformed input.

Parameters

$string string

The encrypted string from encrypt().

$key string

The encryption key used during encrypt().

Default: '0'
$cipher string

OpenSSL cipher name. Defaults to 'aes-256-gcm'.

Default: 'aes-256-gcm'
$options int

OpenSSL options.

Default: OPENSSL_RAW_DATA

Returns

string The original plaintext, or '' on verification failure.

encrypt()

$security->encrypt($string, $key = '0', $cipher = 'aes-256-gcm', $options = OPENSSL_RAW_DATA)

Encrypts a string using AES-256-GCM. The output is formatted as: base64(IV + HMAC-SHA256 + ciphertext), prefixed by the GCM authentication tag, separated by ':::'.

Parameters

$string string

The plain-text string to encrypt.

$key string

The encryption key. Use a long random key in production.

Default: '0'
$cipher string

OpenSSL cipher name. Defaults to 'aes-256-gcm'.

Default: 'aes-256-gcm'
$options int

OPENSSL_RAW_DATA or OPENSSL_ZERO_PADDING.

Default: OPENSSL_RAW_DATA

Returns

string The encrypted, base64-encoded ciphertext.

fileScan() static

Security::fileScan($tmpName, $deleteImmediately = true)

Scans an uploaded file's raw contents for common PHP webshell signatures. Optionally deletes the file immediately when a threat is detected. This is a basic heuristic check and not a substitute for a full AV scan.

Parameters

$tmpName string

The temporary file path from $_FILES.

$deleteImmediately bool

When true, unlinks the file on detection.

Default: true

Returns

bool True when the file appears safe, false when a threat is detected.

getCSRFToken()

$security->getCSRFToken()

Returns the current CSRF token object, generating one if necessary.

Returns

object{x-csrf-token-name: string, x-csrf-token-key: string}

isCSRFExcluded()

$security->isCSRFExcluded()

Returns true when the current URL is in the CSRF exclusion list or when CSRF protection is globally disabled.

Returns

bool

pass() static

Security::pass($pass, $crypt = false, $timeTarget = 0.04, $cost = 8)

Hashes a password using the strongest available algorithm (Argon2id, Argon2i, or bcrypt). The cost factor is auto-calibrated so that hashing takes at least $timeTarget seconds, ensuring an appropriate work factor regardless of hardware speed.

Parameters

$pass string

The plain-text password to hash.

$crypt int|false

A PASSWORD_* constant to force a specific algorithm. false selects the strongest available algorithm automatically.

Default: false
$timeTarget float

Minimum desired hashing time in seconds. Defaults to 0.04 s.

Default: 0.04
$cost int

Starting cost factor for the calibration loop.

Default: 8

Returns

string The password hash.

setCSRFToken()

$security->setCSRFToken()

Generates a new CSRF token, stores it in a cookie, and caches it statically. When $CSRFTokenConfig['regenerate'] is false and a valid cookie already exists, the existing token is reused.

Returns

string|void The raw token value, or void when an existing token was reused.

verifyCSRFToken()

$security->verifyCSRFToken()

Validates a submitted CSRF token against the stored cookie value. Regenerates the token after a successful POST verification when configured to do so.

Returns

bool True when the token is valid or the request is exempt.

Generated from core/classes/Security.php (FrostMVC ).