开发者

How to check if a request if coming from the same server or different server?

开发者 https://www.devze.com 2023-02-19 02:15 出处:网络
How can I check whether a request being received is sent from the same server?? Say, I\'ve my domain at www.domain.com. Now 开发者_开发问答I\'ve php processing files which will process forms hosted t

How can I check whether a request being received is sent from the same server??

Say, I've my domain at www.domain.com. Now 开发者_开发问答I've php processing files which will process forms hosted through this domain. This processes will be executed only if the requests are sent from within the domain ie. www.domain.com and any other requests sent from other domains will be discarded.


Basically : you cannot.
With the HTTP protocol, each request is independent from the others.


A first idea would be to check the Referer HTTP header, but note that :

  • It can be faked (it's sent by the browser)
  • It is not always present.

So : not a reliable solution.


A possible, and far better than the Referer idea, solution could be to use a nonce :

  • When displaying the form, put a hidden input field in it, containing a random value
  • At the same time, store that random value into the session that correspond to the user.
  • When the form is submitted, check that the hidden field has the same value as the one that's stored in session.

If those two values are not the same, refuse to use the submitted data.

Note : this idea is often used to help fight against CSRF -- and integrated in the "Form" component of some Frameworks (Zend Framework, for instance).


this will check if there is a referer, then it will compare it with current domain, if different then it is from outside referer

if ((isset($_SERVER['HTTP_REFERER']) && !empty($_SERVER['HTTP_REFERER']))) {
if (strtolower(parse_url($_SERVER['HTTP_REFERER'], PHP_URL_HOST)) != strtolower($_SERVER['HTTP_HOST'])) {
// referer not from the same domain
}
}


I know this is an old thread, but some one else can probably find it relevant.

The answer is: Yes you can. But it depends if your Apache/nginx server is set to populate the $_SERVER variable with the required information. Most the server are, so probably you can use this approach.

What you need to do is to extract the HTTP_REFERER from the $_SERVER variable and compare with your domain.

<?php
function requestedByTheSameDomain() {
    $myDomain       = $_SERVER['SCRIPT_URI'];
    $requestsSource = $_SERVER['HTTP_REFERER'];

    return parse_url($myDomain, PHP_URL_HOST) === parse_url($requestsSource, PHP_URL_HOST);
}
0

精彩评论

暂无评论...
验证码 换一张
取 消