CodeIgniter自定义表单中$this->security->get_csrf_hash()函数失效求助
$this->security->get_csrf_hash() Not Working in CodeIgniter Hey there, let’s work through this CSRF token issue together—this is a common gotcha in CodeIgniter, so we’ll cover all the likely fixes step by step:
1. Double-Check CSRF is Enabled in Config
First things first: make sure CSRF protection is turned on in your application/config/config.php file. Look for these settings:
$config['csrf_protection'] = TRUE; $config['csrf_token_name'] = 'csrf_test_name'; // Can be customized, just keep it consistent $config['csrf_cookie_name'] = 'csrf_cookie_name'; $config['csrf_expire'] = 7200;
If csrf_protection is set to FALSE, get_csrf_hash() won’t generate a valid token at all—this is the easiest fix to miss!
2. Ensure the Security Library is Loaded
You can’t call $this->security methods unless the library is loaded. You have two options:
- Load it manually in your controller:
$this->load->library('security'); - Auto-load it in
application/config/autoload.phpso it’s available everywhere:$autoload['libraries'] = array('security');
If the library isn’t loaded, you’ll either get an error or an empty value from get_csrf_hash().
3. Pair the Hash with the Correct Token Name in Your Form
A CSRF token needs both the token name and hash to work. Don’t hardcode the name—use the helper method to match your config:
<form method="post" action="your_controller/your_method"> <input type="hidden" name="<?php echo $this->security->get_csrf_token_name(); ?>" value="<?php echo $this->security->get_csrf_hash(); ?>" /> <!-- Your other form fields here --> <button type="submit">Submit</button> </form>
If the name doesn’t match what CodeIgniter expects in the config, your form submission will fail CSRF validation.
4. Rule Out Stale Cookies/Cache
Sometimes old CSRF cookies can cause mismatches. Clear your browser’s cookies and cache for your site, then reload the page to generate a fresh token. This often fixes weird, intermittent issues.
5. Check for Route Exclusions
If you’ve set csrf_exclude_uris in your config, make sure your target controller/method isn’t on that list. If it is, CSRF protection is disabled for that route, so get_csrf_hash() won’t produce a valid token:
$config['csrf_exclude_uris'] = array('auth/login', 'api/*');
6. Test with a Minimal Example
If nothing else works, create a stripped-down controller and view to isolate the issue. For example:
Test Controller (Test.php):
<?php class Test extends CI_Controller { public function index() { $this->load->library('security'); $data['csrf_name'] = $this->security->get_csrf_token_name(); $data['csrf_hash'] = $this->security->get_csrf_hash(); $this->load->view('test_form', $data); } public function submit() { if ($this->input->post()) { echo "Form submitted successfully!"; } } }
Test View (test_form.php):
<form method="post" action="<?php echo site_url('test/submit'); ?>"> <input type="hidden" name="<?php echo $csrf_name; ?>" value="<?php echo $csrf_hash; ?>" /> <input type="text" name="test_field" placeholder="Test input" /> <button type="submit">Submit</button> </form>
If this works, the problem is likely in your original code’s setup—maybe conflicting libraries, incorrect routing, or a typo you missed.
内容的提问来源于stack exchange,提问作者Nikul Panchal

