Class CsrfProtectionFilter
- java.lang.Object
-
- org.glassfish.jersey.server.filter.CsrfProtectionFilter
-
- All Implemented Interfaces:
ContainerRequestFilter
@Priority(1000) public class CsrfProtectionFilter extends Object implements ContainerRequestFilter
Simple server-side request filter that implements CSRF protection as per the Guidelines for Implementation of REST by NSA (section IV.F) and section 4.3 of this paper. If you add it to the request filters of your application, it will check for X-Requested-By header in each request except for those that don't change state (GET, OPTIONS, HEAD). If the header is not found, it returnsResponse.Status.BAD_REQUESTresponse back to the client.- Author:
- Martin Matula
- See Also:
CsrfProtectionFilter
-
-
Field Summary
Fields Modifier and Type Field Description static StringHEADER_NAMEName of the header this filter will attach to the request.
-
Constructor Summary
Constructors Constructor Description CsrfProtectionFilter()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidfilter(ContainerRequestContext rc)Filter method called before a request has been dispatched to a resource.
-
-
-
Field Detail
-
HEADER_NAME
public static final String HEADER_NAME
Name of the header this filter will attach to the request.- See Also:
- Constant Field Values
-
-
Method Detail
-
filter
public void filter(ContainerRequestContext rc) throws IOException
Description copied from interface:ContainerRequestFilterFilter method called before a request has been dispatched to a resource.Filters in the filter chain are ordered according to their
jakarta.annotation.Priorityclass-level annotation value. If a request filter produces a response by callingContainerRequestContext.abortWith(jakarta.ws.rs.core.Response)method, the execution of the (either pre-match or post-match) request filter chain is stopped and the response is passed to the corresponding response filter chain (either pre-match or post-match). For example, a pre-match caching filter may produce a response in this way, which would effectively skip any post-match request filters as well as post-match response filters. Note however that a responses produced in this manner would still be processed by the pre-match response filter chain.- Specified by:
filterin interfaceContainerRequestFilter- Parameters:
rc- request context.- Throws:
IOException- if an I/O exception occurs.- See Also:
PreMatching
-
-