Class CookieCsrfTokenRepository

java.lang.Object
com.codename1.backend.security.CookieCsrfTokenRepository
All Implemented Interfaces:
CsrfTokenRepository

public final class CookieCsrfTokenRepository extends Object implements CsrfTokenRepository

Keeps the token in a cookie, XSRF-TOKEN, for a page whose script reads the cookie and sends its value back in the X-XSRF-TOKEN header -- the convention Angular and axios follow. The token is also kept in the session so a sibling subdomain cannot inject a cookie and submit a matching value.

http.csrf(csrf -> csrf.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()));

A script can only read the cookie when it is not HttpOnly, which is what withHttpOnlyFalse() is for. Because the script has the token as the cookie holds it, a chain with this repository accepts the token unmasked in the header as well as masked. A cookie is trusted only when it matches the token issued to the current session. Tokens copied from other sessions are rejected.