Class CsrfFilter

java.lang.Object
com.codename1.backend.security.CsrfFilter
All Implemented Interfaces:
SecurityFilter

public final class CsrfFilter extends Object implements SecurityFilter

Refuses a state-changing request that does not carry the chain's CSRF token.

GET, HEAD, TRACE and OPTIONS pass: they are not supposed to change anything. Every other request must send the token back, in the header or the form field the token names, and is answered 403 by the chain's AccessDeniedHandler when it does not.

The token a page is given is masked: the stored value XORed with random bytes that are sent along with it. Every response therefore carries a different string for the same token, which is what keeps a compressed response from leaking it to an attacker who can influence part of the body.

  • Method Details