Interface SecurityFilter

All Known Implementing Classes:
AnonymousAuthenticationFilter, ApiKeyAuthenticationFilter, AuthorizationFilter, BasicAuthenticationFilter, BearerTokenAuthenticationFilter, CsrfFilter, DefaultLoginPageGeneratingFilter, ExceptionTranslationFilter, HeaderWriterFilter, LogoutFilter, OAuth2AuthorizationEndpointFilter, OAuth2AuthorizationRequestRedirectFilter, OAuth2AuthorizationServerFilter, OAuth2LoginAuthenticationFilter, RateLimitFilter, RememberMeAuthenticationFilter, SecondFactorAuthenticationFilter, SecurityContextHolderFilter, UsernamePasswordAuthenticationFilter, WebAuthnAuthenticationFilter, WebAuthnRegistrationFilter

public interface SecurityFilter

One step of a SecurityFilterChain. A filter answers the request itself, or asks the rest of the chain and returns -- or replaces -- what comes back.

SecurityFilter audit = (request, chain) -> {
    log(request.getMethod() + " " + request.pathFrom(0));
    return chain.doFilter(request);
};
http.addFilterBefore(audit, AuthorizationFilter.class);

The response the chain returns may be one a handler shares between requests, so a filter does not write into it: a header for this request's answer goes through SecurityExchange.setResponseHeader(String, String).