Interface CsrfToken

All Known Implementing Classes:
DefaultCsrfToken

public interface CsrfToken

The token a page sends back with a state-changing request to show the request came from the application's own pages.

A controller receives the current one by declaring a parameter of this type, to put in a form or hand to a script:

@GetMapping("/csrf")
public Map csrf(CsrfToken token) {
    Map out = new LinkedHashMap();
    out.put("headerName", token.getHeaderName());
    out.put("token", token.getToken());
    return out;
}
  • Method Summary

    Modifier and Type
    Method
    Description
    The header a script sends the token in: X-CSRF-TOKEN.
    The form field a page sends the token in: _csrf.
    The value to send.
  • Method Details

    • getHeaderName

      String getHeaderName()
      The header a script sends the token in: X-CSRF-TOKEN.
    • getParameterName

      String getParameterName()
      The form field a page sends the token in: _csrf.
    • getToken

      String getToken()
      The value to send. From a controller parameter it is masked: different in every response, and every one of them accepted.