From e70239230e4269eff3cb6010ddb967cfb01634ef Mon Sep 17 00:00:00 2001 From: Christopher Davis Date: Wed, 30 Mar 2022 08:21:08 -0500 Subject: [PATCH] Use `$procedure` in `isDisabled` Method Check Seems like this one got missed and it was always checking the `requried` key of methods. --- Service/CsrfRequestEvaluator.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Service/CsrfRequestEvaluator.php b/Service/CsrfRequestEvaluator.php index 6e2f760..a7a8b1b 100644 --- a/Service/CsrfRequestEvaluator.php +++ b/Service/CsrfRequestEvaluator.php @@ -160,7 +160,7 @@ public function isDisabled(string $procedure, Request $request, ?Response $respo || empty($csrf[$procedure]) || (!empty($csrf['exclude']) && is_array($csrf['exclude']) && in_array($attributes->get('_route'), $csrf['exclude'], true)) || (!empty($csrf['condition']) && $this->evaluateCondition($csrf['condition'], $request, $response) === false) - || (is_array($csrf[$procedure]) && !in_array($request->getMethod(), $csrf[self::REQUIRE], true)) + || (is_array($csrf[$procedure]) && !in_array($request->getMethod(), $csrf[$procedure], true)) ; }