Cryptographic utilities for generating and validating CSRF tokens.
This trait should not be used as a general purpose encryption utility.
Attributes
- Companion
- object
- Graph
-
- Supertypes
-
class Objecttrait Matchableclass Any
- Known subtypes
-
class DefaultCSRFTokenSigner
Members list
Value members
Abstract methods
Compare two signed tokens
Compare two signed tokens
Attributes
Extract a signed token that was signed by signToken(String).
Extract a signed token that was signed by signToken(String).
Value parameters
- token
-
The signed token to extract.
Attributes
- Returns
-
The verified raw token, or None if the token isn't valid.
Generates a signed token.
Generates a signed token.
Attributes
Generates a cryptographically secure token.
Generates a cryptographically secure token.
Attributes
Sign a token. This produces a new token, that has this token signed with a nonce.
Sign a token. This produces a new token, that has this token signed with a nonce.
This primarily exists to defeat the BREACH vulnerability, as it allows the token to effectively be random per request, without actually changing the value.
Value parameters
- token
-
The token to sign
Attributes
- Returns
-
The signed token
Deprecated methods
Constant time equals method.
Constant time equals method.
Given a length that both Strings are equal to, this method will always run in constant time. This prevents timing attacks.
Attributes
- Deprecated
-
Please use
java.security.MessageDigest.isEqual(a.getBytes("utf-8"), b.getBytes("utf-8"))over this method.