Class CsrfConfigurer
java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.CsrfConfigurer
Protection against cross-site request forgery. On by default; see
CsrfFilter for what it requires of a request.
http.csrf(csrf -> csrf
.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
.ignoringRequestMatchers("/webhooks/**"));
A chain whose clients are not browsers -- an API reached with a bearer token
or HTTP Basic from a program -- has nothing to protect and turns it off:
http.csrf(csrf -> csrf.disable()).
-
Method Summary
Modifier and TypeMethodDescriptionvoidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.csrfTokenRepository(CsrfTokenRepository csrfTokenRepository) Where the token is kept; the session unless set.ignoringRequestMatchers(RequestMatcher... requestMatchers) Requests left alone whatever their method.ignoringRequestMatchers(String... patterns) Requests left alone whatever their method, by Ant pattern: an endpoint another server calls, which authenticates some other way.requireCsrfProtectionMatcher(RequestMatcher requireCsrfProtectionMatcher) Which requests must carry the token; every one that is not a GET, HEAD, TRACE or OPTIONS unless set.Methods inherited from class SecurityConfigurer
disable, getBuilder, init
-
Method Details
-
csrfTokenRepository
Where the token is kept; the session unless set. -
requireCsrfProtectionMatcher
Which requests must carry the token; every one that is not a GET, HEAD, TRACE or OPTIONS unless set. -
ignoringRequestMatchers
Requests left alone whatever their method, by Ant pattern: an endpoint another server calls, which authenticates some other way. -
ignoringRequestMatchers
Requests left alone whatever their method. -
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-