Class CsrfConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.CsrfConfigurer

public final class CsrfConfigurer extends SecurityConfigurer

Protection against cross-site request forgery. On by default; see CsrfFilter for what it requires of a request.

http.csrf(csrf -> csrf
        .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
        .ignoringRequestMatchers("/webhooks/**"));

A chain whose clients are not browsers -- an API reached with a bearer token or HTTP Basic from a program -- has nothing to protect and turns it off: http.csrf(csrf -> csrf.disable()).

  • Method Details

    • csrfTokenRepository

      public CsrfConfigurer csrfTokenRepository(CsrfTokenRepository csrfTokenRepository)
      Where the token is kept; the session unless set.
    • requireCsrfProtectionMatcher

      public CsrfConfigurer requireCsrfProtectionMatcher(RequestMatcher requireCsrfProtectionMatcher)
      Which requests must carry the token; every one that is not a GET, HEAD, TRACE or OPTIONS unless set.
    • ignoringRequestMatchers

      public CsrfConfigurer ignoringRequestMatchers(String... patterns)
      Requests left alone whatever their method, by Ant pattern: an endpoint another server calls, which authenticates some other way.
    • ignoringRequestMatchers

      public CsrfConfigurer ignoringRequestMatchers(RequestMatcher... requestMatchers)
      Requests left alone whatever their method.
    • configure

      public void configure(HttpSecurity http)
      Description copied from class: SecurityConfigurer
      Adds this part's filters; nothing by default.
      Overrides:
      configure in class SecurityConfigurer