Interface CsrfToken
- All Known Implementing Classes:
DefaultCsrfToken
public interface CsrfToken
The token a page sends back with a state-changing request to show the request came from the application's own pages.
A controller receives the current one by declaring a parameter of this type, to put in a form or hand to a script:
@GetMapping("/csrf")
public Map csrf(CsrfToken token) {
Map out = new LinkedHashMap();
out.put("headerName", token.getHeaderName());
out.put("token", token.getToken());
return out;
}
-
Method Summary
Modifier and TypeMethodDescriptionThe header a script sends the token in:X-CSRF-TOKEN.The form field a page sends the token in:_csrf.getToken()The value to send.
-
Method Details
-
getHeaderName
String getHeaderName()The header a script sends the token in:X-CSRF-TOKEN. -
getParameterName
String getParameterName()The form field a page sends the token in:_csrf. -
getToken
String getToken()The value to send. From a controller parameter it is masked: different in every response, and every one of them accepted.
-