public class CSRFUtil extends Object
CSRFUtil
...Modifier and Type | Field and Description |
---|---|
static String |
DISABLED
Constant used to
|
Constructor and Description |
---|
CSRFUtil(String config)
Creates a new instance from the specified configuration, which defines
the behaviour of the referrer based CSRF protection as follows:
If config is
null or empty string the default
behaviour is to allow only requests with an empty referrer header or a
referrer host equal to the server host
A comma separated list of additional allowed referrer hosts which are
valid in addition to default behaviour (see above).
The value DISABLED may be used to disable the referrer checking altogether
|
public static final String DISABLED
public CSRFUtil(String config)
null
or empty string the default
behaviour is to allow only requests with an empty referrer header or a
referrer host equal to the server hostDISABLED
may be used to disable the referrer checking altogetherconfig
- The configuration value which may be any of the following:
null
or empty string for the default behaviour, which
only allows requests with an empty referrer header or a
referrer host equal to the server hostDISABLED
in order to disable the referrer checking altogetherpublic boolean isValidRequest(javax.servlet.http.HttpServletRequest request) throws MalformedURLException
MalformedURLException
Copyright © 2004-2012 Apache Software Foundation. All Rights Reserved.