CsrfTokenController.php

Same filename in other branches
  1. 9 core/modules/system/src/Controller/CsrfTokenController.php
  2. 10 core/modules/system/src/Controller/CsrfTokenController.php
  3. 11.x core/modules/system/src/Controller/CsrfTokenController.php

Namespace

Drupal\system\Controller

File

core/modules/system/src/Controller/CsrfTokenController.php

View source
<?php

namespace Drupal\system\Controller;

use Drupal\Core\Access\CsrfRequestHeaderAccessCheck;
use Drupal\Core\Access\CsrfTokenGenerator;
use Drupal\Core\DependencyInjection\ContainerInjectionInterface;
use Symfony\Component\DependencyInjection\ContainerInterface;
use Symfony\Component\HttpFoundation\Response;

/**
 * Returns responses for CSRF token routes.
 */
class CsrfTokenController implements ContainerInjectionInterface {
    
    /**
     * The CSRF token generator.
     *
     * @var \Drupal\Core\Access\CsrfTokenGenerator
     */
    protected $tokenGenerator;
    
    /**
     * Constructs a new CsrfTokenController object.
     *
     * @param \Drupal\Core\Access\CsrfTokenGenerator $token_generator
     *   The CSRF token generator.
     */
    public function __construct(CsrfTokenGenerator $token_generator) {
        $this->tokenGenerator = $token_generator;
    }
    
    /**
     * {@inheritdoc}
     */
    public static function create(ContainerInterface $container) {
        return new static($container->get('csrf_token'));
    }
    
    /**
     * Returns a CSRF protecting session token.
     *
     * @return \Symfony\Component\HttpFoundation\Response
     *   The response object.
     */
    public function csrfToken() {
        return new Response($this->tokenGenerator
            ->get(CsrfRequestHeaderAccessCheck::TOKEN_KEY), 200, [
            'Content-Type' => 'text/plain',
        ]);
    }

}

Classes

Title Deprecated Summary
CsrfTokenController Returns responses for CSRF token routes.

Buggy or inaccurate documentation? Please file an issue. Need support? Need help programming? Connect with the Drupal community.