public class CsrfPreventionFilter extends CsrfPreventionFilterBase
HttpServletResponse.encodeRedirectURL(String) and HttpServletResponse.encodeURL(String) are used
to encode all URLs returned to the client
CSRF protection is enabled by generating random nonce values which are
stored in the client's HTTP session. Each URL encoded using
HttpServletResponse.encodeURL(String) has a URL parameter added
which, when sent to the server in a future request, will be checked
against this stored set of nonces for validity.
Some URLs should be accessible even without a valid nonce parameter value.
These URLs are known as "entry points" because clients should be able to
"enter" the application without first establishing any valid tokens. These
are configured with the entryPoints filter
init-param.
Some URLs should not have nonce parameters added to them at all
| Modifier and Type | Class and Description |
|---|---|
protected static class |
CsrfPreventionFilter.CsrfResponseWrapper |
protected static class |
CsrfPreventionFilter.LruCache<T>
Despite its name, this is a FIFO cache not an LRU cache.
|
protected static class |
CsrfPreventionFilter.MimePredicate
A no-nonce Predicate that evaluates a MIME type instead of a URL.
|
protected static interface |
CsrfPreventionFilter.NonceCache<T> |
protected static class |
CsrfPreventionFilter.PatternPredicate
A no-nonce Predicate that matches a regular expression.
|
protected static class |
CsrfPreventionFilter.PrefixPredicate
A no-nonce Predicate that matches a prefix.
|
protected static class |
CsrfPreventionFilter.SuffixPredicate
A no-nonce Predicate that matches a suffix.
|
sm| Constructor and Description |
|---|
CsrfPreventionFilter() |
| Modifier and Type | Method and Description |
|---|---|
protected CsrfPreventionFilter.NonceCache<java.lang.String> |
createNonceCache(HttpServletRequest request,
HttpSession session)
Create a new
CsrfPreventionFilter.NonceCache and store in the HttpSession. |
protected static java.util.function.Predicate<java.lang.String> |
createNoNoncePredicate(ServletContext context,
java.lang.String pattern)
Creates a predicate that can match the specified type of pattern.
|
protected static java.util.Collection<java.util.function.Predicate<java.lang.String>> |
createNoNoncePredicates(ServletContext context,
java.lang.String patterns)
Creates a collection of matchers from a comma-separated string of patterns.
|
void |
doFilter(ServletRequest request,
ServletResponse response,
FilterChain chain)
The
doFilter method of the Filter is called by the container each time a request/response pair is
passed through the chain due to a client request for a resource at the end of the chain. |
protected boolean |
enforce(HttpServletRequest req,
java.lang.String requestedPath)
Check to see if the request and path should be enforced or only
observed and reported.
|
protected CsrfPreventionFilter.NonceCache<java.lang.String> |
getNonceCache(HttpServletRequest request,
HttpSession session)
Obtain the
CsrfPreventionFilter.NonceCache associated with the request and/or session. |
void |
init(FilterConfig filterConfig)
Iterates over the configuration parameters and either logs a warning, or throws an exception for any parameter
that does not have a matching setter in this filter.
|
boolean |
isEnforce()
Gets the flag to enforce CSRF protection or just log failures as DEBUG
messages.
|
void |
setEnforce(boolean enforce)
Sets the flag to enforce CSRF protection or just log failures as DEBUG
messages.
|
void |
setEntryPoints(java.lang.String entryPoints)
Entry points are URLs that will not be tested for the presence of a valid nonce.
|
void |
setNonceCacheSize(int nonceCacheSize)
Sets the number of previously issued nonces that will be cached on a LRU basis to support parallel requests,
limited use of the refresh and back in the browser and similar behaviors that may result in the submission of a
previous nonce rather than the current one.
|
void |
setNonceRequestParameterName(java.lang.String parameterName)
Sets the request parameter name to use for CSRF nonces.
|
void |
setNoNonceURLPatterns(java.lang.String patterns)
Sets the list of URL patterns to suppress nonce-addition for.
|
protected boolean |
skipNonceCheck(HttpServletRequest request) |
protected boolean |
skipNonceGeneration(HttpServletRequest request)
Determines whether a nonce should be created.
|
generateNonce, generateNonce, getDenyStatus, getLogger, getRequestedPath, isConfigProblemFatal, setDenyStatus, setRandomClasspublic void setEntryPoints(java.lang.String entryPoints)
entryPoints - Comma separated list of URLs to be configured as entry points.public void setNonceCacheSize(int nonceCacheSize)
nonceCacheSize - The number of nonces to cachepublic void setNonceRequestParameterName(java.lang.String parameterName)
parameterName - The request parameter name to use for CSRF nonces.public void setEnforce(boolean enforce)
enforce - true to enforce CSRF protection or
false to log DEBUG messages and allow
all requests.public boolean isEnforce()
true if CSRF protection will be enforced or
false if all requests will be allowed and
failures will be logged as DEBUG messages.public void setNoNonceURLPatterns(java.lang.String patterns)
patterns - A comma-separated list of URL patterns that will not
have nonces added to them. Patterns may begin or end with a
* character to denote a suffix-match or
prefix-match. Any matched URL will not have a CSRF nonce
added to it when passed through
HttpServletResponse.encodeURL(String).protected static java.util.Collection<java.util.function.Predicate<java.lang.String>> createNoNoncePredicates(ServletContext context, java.lang.String patterns)
context - the Servlet contextpatterns - A comma-separated string of URL matching patterns.protected static java.util.function.Predicate<java.lang.String> createNoNoncePredicate(ServletContext context, java.lang.String pattern)
context - the Servlet contextpattern - The pattern to match e.g. *.foo or
/bar/*.null if the pattern is null or blank.public void init(FilterConfig filterConfig) throws ServletException
FilterBaseinit in interface Filterinit in class CsrfPreventionFilterBasefilterConfig - The configuration information associated with the filter instance being initialisedServletException - if FilterBase.isConfigProblemFatal() returns true and a configured parameter does
not have a matching setterpublic void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws java.io.IOException, ServletException
javax.servlet.FilterdoFilter method of the Filter is called by the container each time a request/response pair is
passed through the chain due to a client request for a resource at the end of the chain. The FilterChain passed
in to this method allows the Filter to pass on the request and response to the next entity in the chain.
A typical implementation of this method would follow the following pattern:-
1. Examine the request
2. Optionally wrap the request object with a custom implementation to filter content or headers for input
filtering
3. Optionally wrap the response object with a custom implementation to filter content or headers for output
filtering
4. a) Either invoke the next entity in the chain using the FilterChain object
(chain.doFilter()),
4. b) or not pass on the request/response pair to the next entity in the filter chain to block
the request processing
5. Directly set headers on the response after invocation of the next entity in the filter chain.
request - The request to processresponse - The response associated with the requestchain - Provides access to the next filter in the chain for this filter to pass the request and response
to for further processingjava.io.IOException - if an I/O error occurs during this filter's processing of the requestServletException - if the processing fails for any other reasonprotected boolean enforce(HttpServletRequest req, java.lang.String requestedPath)
requestedPath parameter is purely
a performance optimization to avoid calling
CsrfPreventionFilterBase.getRequestedPath(HttpServletRequest) multiple times.req - The request.requestedPath - The path of the request being evaluated.true if the CSRF prevention should be enforced,
false if the CSRF prevention should only be
logged in DEBUG mode.protected boolean skipNonceCheck(HttpServletRequest request)
protected boolean skipNonceGeneration(HttpServletRequest request)
request - The request that triggered the need to potentially create the nonce.true if a nonce should be created, otherwise falseprotected CsrfPreventionFilter.NonceCache<java.lang.String> createNonceCache(HttpServletRequest request, HttpSession session)
CsrfPreventionFilter.NonceCache and store in the HttpSession. This method is provided primarily for the
benefit of sub-classes that wish to customise this behaviour.request - The request that triggered the need to create the nonce cache. Unused by the default
implementation.session - The session associated with the request.CsrfPreventionFilter.NonceCacheprotected CsrfPreventionFilter.NonceCache<java.lang.String> getNonceCache(HttpServletRequest request, HttpSession session)
CsrfPreventionFilter.NonceCache associated with the request and/or session. This method is provided primarily for
the benefit of sub-classes that wish to customise this behaviour.request - The request that triggered the need to obtain the nonce cache. Unused by the default
implementation.session - The session associated with the request.CsrfPreventionFilter.NonceCache currently associated with the request and/or sessionCopyright © 2000-2024 Apache Software Foundation.
Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo are either registered trademarks or trademarks of the Apache Software Foundation.