FrostMVC\Security
use FrostMVC\Security;
Security utilities: password hashing, CSRF token management, AES-256-GCM encryption, and basic file upload content scanning.
| Property | Type | Description |
|---|---|---|
| Security::$CSRFTokenConfig | mixed |
| ->__construct() | — |
| ->checkCSRFToken() | Validates the CSRF token on every incoming POST request. On failure, responds based on the submission context: - XHR forms: JSON error response - Inline forms: sets a flash error message - Standard forms: renders the error page with 403 When no POST data is present, a new token is generated for the next request. |
| ->decrypt() | Decrypts a string produced by encrypt(). Verifies the HMAC-SHA256 before returning the plaintext. Returns an empty string on tampered or malformed input. |
| ->encrypt() | Encrypts a string using AES-256-GCM. The output is formatted as: base64(IV + HMAC-SHA256 + ciphertext), prefixed by the GCM authentication tag, separated by ':::'. |
| ::fileScan() | Scans an uploaded file's raw contents for common PHP webshell signatures. Optionally deletes the file immediately when a threat is detected. This is a basic heuristic check and not a substitute for a full AV scan. |
| ->getCSRFToken() | Returns the current CSRF token object, generating one if necessary. |
| ->isCSRFExcluded() | Returns true when the current URL is in the CSRF exclusion list or when CSRF protection is globally disabled. |
| ::pass() | Hashes a password using the strongest available algorithm (Argon2id, Argon2i, or bcrypt). The cost factor is auto-calibrated so that hashing takes at least $timeTarget seconds, ensuring an appropriate work factor regardless of hardware speed. |
| ->setCSRFToken() | Generates a new CSRF token, stores it in a cookie, and caches it statically. When $CSRFTokenConfig['regenerate'] is false and a valid cookie already exists, the existing token is reused. |
| ->verifyCSRFToken() | Validates a submitted CSRF token against the stored cookie value. Regenerates the token after a successful POST verification when configured to do so. |
$security->__construct()
No description yet.
$security->checkCSRFToken()
Validates the CSRF token on every incoming POST request. On failure, responds based on the submission context: - XHR forms: JSON error response - Inline forms: sets a flash error message - Standard forms: renders the error page with 403 When no POST data is present, a new token is generated for the next request.
$security->decrypt($string, $key = '0', $cipher = 'aes-256-gcm', $options = OPENSSL_RAW_DATA)
Decrypts a string produced by encrypt(). Verifies the HMAC-SHA256 before returning the plaintext. Returns an empty string on tampered or malformed input.
| $string | string |
The encrypted string from encrypt(). |
| $key | string |
The encryption key used during encrypt(). Default:'0' |
| $cipher | string |
OpenSSL cipher name. Defaults to 'aes-256-gcm'. Default:'aes-256-gcm' |
| $options | int |
OpenSSL options. Default:OPENSSL_RAW_DATA |
string The original plaintext, or '' on verification failure.
$security->encrypt($string, $key = '0', $cipher = 'aes-256-gcm', $options = OPENSSL_RAW_DATA)
Encrypts a string using AES-256-GCM. The output is formatted as: base64(IV + HMAC-SHA256 + ciphertext), prefixed by the GCM authentication tag, separated by ':::'.
| $string | string |
The plain-text string to encrypt. |
| $key | string |
The encryption key. Use a long random key in production. Default:'0' |
| $cipher | string |
OpenSSL cipher name. Defaults to 'aes-256-gcm'. Default:'aes-256-gcm' |
| $options | int |
OPENSSL_RAW_DATA or OPENSSL_ZERO_PADDING. Default:OPENSSL_RAW_DATA |
string The encrypted, base64-encoded ciphertext.
Security::fileScan($tmpName, $deleteImmediately = true)
Scans an uploaded file's raw contents for common PHP webshell signatures. Optionally deletes the file immediately when a threat is detected. This is a basic heuristic check and not a substitute for a full AV scan.
| $tmpName | string |
The temporary file path from $_FILES. |
| $deleteImmediately | bool |
When true, unlinks the file on detection. Default:true |
bool True when the file appears safe, false when a threat is detected.
$security->getCSRFToken()
Returns the current CSRF token object, generating one if necessary.
object{x-csrf-token-name: string, x-csrf-token-key: string}
$security->isCSRFExcluded()
Returns true when the current URL is in the CSRF exclusion list or when CSRF protection is globally disabled.
bool
Security::pass($pass, $crypt = false, $timeTarget = 0.04, $cost = 8)
Hashes a password using the strongest available algorithm (Argon2id, Argon2i, or bcrypt). The cost factor is auto-calibrated so that hashing takes at least $timeTarget seconds, ensuring an appropriate work factor regardless of hardware speed.
| $pass | string |
The plain-text password to hash. |
| $crypt | int|false |
A PASSWORD_* constant to force a specific algorithm. false selects the strongest available algorithm automatically. Default:false |
| $timeTarget | float |
Minimum desired hashing time in seconds. Defaults to 0.04 s. Default:0.04 |
| $cost | int |
Starting cost factor for the calibration loop. Default:8 |
string The password hash.
$security->setCSRFToken()
Generates a new CSRF token, stores it in a cookie, and caches it statically. When $CSRFTokenConfig['regenerate'] is false and a valid cookie already exists, the existing token is reused.
string|void The raw token value, or void when an existing token was reused.
$security->verifyCSRFToken()
Validates a submitted CSRF token against the stored cookie value. Regenerates the token after a successful POST verification when configured to do so.
bool True when the token is valid or the request is exempt.
Generated from core/classes/Security.php (FrostMVC ).