Class CsrfFilter
java.lang.Object
com.codename1.backend.security.CsrfFilter
- All Implemented Interfaces:
SecurityFilter
Refuses a state-changing request that does not carry the chain's CSRF token.
GET, HEAD, TRACE and OPTIONS pass: they are not supposed to change anything.
Every other request must send the token back, in the header or the form
field the token names, and is answered 403 by the chain's
AccessDeniedHandler when it does not.
The token a page is given is masked: the stored value XORed with random bytes that are sent along with it. Every response therefore carries a different string for the same token, which is what keeps a compressed response from leaking it to an attacker who can influence part of the body.
-
Method Summary
Modifier and TypeMethodDescriptiondoFilter(HttpServer.Request request, FilterChain chain) The answer torequest; null when nothing under the chain routes it, which the server answers 404.static CsrfTokengetToken(HttpServer.Request request) The CSRF token ofrequest, for a page or a script to send back, or null when the request is under no chain or its chain has CSRF protection off.
-
Method Details
-
getToken
The CSRF token ofrequest, for a page or a script to send back, or null when the request is under no chain or its chain has CSRF protection off. Asking makes the token exist: with the session repository that starts a session. -
doFilter
Description copied from interface:SecurityFilterThe answer torequest; null when nothing under the chain routes it, which the server answers 404.- Specified by:
doFilterin interfaceSecurityFilter- Throws:
Exception
-