You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CodeIgniter自定义表单中$this->security->get_csrf_hash()函数失效求助

Troubleshooting $this->security->get_csrf_hash() Not Working in CodeIgniter

Hey there, let’s work through this CSRF token issue together—this is a common gotcha in CodeIgniter, so we’ll cover all the likely fixes step by step:

1. Double-Check CSRF is Enabled in Config

First things first: make sure CSRF protection is turned on in your application/config/config.php file. Look for these settings:

$config['csrf_protection'] = TRUE;
$config['csrf_token_name'] = 'csrf_test_name'; // Can be customized, just keep it consistent
$config['csrf_cookie_name'] = 'csrf_cookie_name';
$config['csrf_expire'] = 7200;

If csrf_protection is set to FALSE, get_csrf_hash() won’t generate a valid token at all—this is the easiest fix to miss!

2. Ensure the Security Library is Loaded

You can’t call $this->security methods unless the library is loaded. You have two options:

  • Load it manually in your controller:
    $this->load->library('security');
    
  • Auto-load it in application/config/autoload.php so it’s available everywhere:
    $autoload['libraries'] = array('security');
    

If the library isn’t loaded, you’ll either get an error or an empty value from get_csrf_hash().

3. Pair the Hash with the Correct Token Name in Your Form

A CSRF token needs both the token name and hash to work. Don’t hardcode the name—use the helper method to match your config:

<form method="post" action="your_controller/your_method">
    <input type="hidden" name="<?php echo $this->security->get_csrf_token_name(); ?>" value="<?php echo $this->security->get_csrf_hash(); ?>" />
    <!-- Your other form fields here -->
    <button type="submit">Submit</button>
</form>

If the name doesn’t match what CodeIgniter expects in the config, your form submission will fail CSRF validation.

4. Rule Out Stale Cookies/Cache

Sometimes old CSRF cookies can cause mismatches. Clear your browser’s cookies and cache for your site, then reload the page to generate a fresh token. This often fixes weird, intermittent issues.

5. Check for Route Exclusions

If you’ve set csrf_exclude_uris in your config, make sure your target controller/method isn’t on that list. If it is, CSRF protection is disabled for that route, so get_csrf_hash() won’t produce a valid token:

$config['csrf_exclude_uris'] = array('auth/login', 'api/*');

6. Test with a Minimal Example

If nothing else works, create a stripped-down controller and view to isolate the issue. For example:

Test Controller (Test.php):

<?php
class Test extends CI_Controller {
    public function index() {
        $this->load->library('security');
        $data['csrf_name'] = $this->security->get_csrf_token_name();
        $data['csrf_hash'] = $this->security->get_csrf_hash();
        $this->load->view('test_form', $data);
    }

    public function submit() {
        if ($this->input->post()) {
            echo "Form submitted successfully!";
        }
    }
}

Test View (test_form.php):

<form method="post" action="<?php echo site_url('test/submit'); ?>">
    <input type="hidden" name="<?php echo $csrf_name; ?>" value="<?php echo $csrf_hash; ?>" />
    <input type="text" name="test_field" placeholder="Test input" />
    <button type="submit">Submit</button>
</form>

If this works, the problem is likely in your original code’s setup—maybe conflicting libraries, incorrect routing, or a typo you missed.


内容的提问来源于stack exchange,提问作者Nikul Panchal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:38:49