Class CookieCsrfTokenRepository
java.lang.Object
com.codename1.backend.security.CookieCsrfTokenRepository
- All Implemented Interfaces:
CsrfTokenRepository
Keeps the token in a cookie, XSRF-TOKEN, for a page whose script reads the
cookie and sends its value back in the X-XSRF-TOKEN header -- the
convention Angular and axios follow. The token is also kept in the session
so a sibling subdomain cannot inject a cookie and submit a matching value.
http.csrf(csrf -> csrf.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()));
A script can only read the cookie when it is not HttpOnly, which is what
withHttpOnlyFalse() is for. Because the script has the token as the cookie
holds it, a chain with this repository accepts the token unmasked in the
header as well as masked. A cookie is trusted only when it matches the
token issued to the current session. Tokens copied from other sessions
are rejected.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptiongenerateToken(HttpServer.Request request) A new token, not yet stored.loadToken(HttpServer.Request request) The stored token, or null when the client has none.voidsaveToken(CsrfToken token, HttpServer.Request request) Storestokenfor the client; null forgets the stored one.voidsetCookieHttpOnly(boolean cookieHttpOnly) voidsetCookieName(String cookieName) voidsetCookiePath(String cookiePath) The cookie's path;/unless set.voidsetHeaderName(String headerName) voidsetParameterName(String parameterName) static CookieCsrfTokenRepositoryA repository whose cookie a script can read.
-
Constructor Details
-
CookieCsrfTokenRepository
public CookieCsrfTokenRepository()
-
-
Method Details
-
withHttpOnlyFalse
A repository whose cookie a script can read. -
setCookieName
-
setHeaderName
-
setParameterName
-
setCookiePath
The cookie's path;/unless set. -
setCookieHttpOnly
public void setCookieHttpOnly(boolean cookieHttpOnly) -
generateToken
Description copied from interface:CsrfTokenRepositoryA new token, not yet stored.- Specified by:
generateTokenin interfaceCsrfTokenRepository
-
saveToken
Description copied from interface:CsrfTokenRepositoryStorestokenfor the client; null forgets the stored one.- Specified by:
saveTokenin interfaceCsrfTokenRepository
-
loadToken
Description copied from interface:CsrfTokenRepositoryThe stored token, or null when the client has none.- Specified by:
loadTokenin interfaceCsrfTokenRepository
-