Interface CsrfTokenRepository
-
- All Known Implementing Classes:
CookieCsrfTokenRepository,HttpSessionCsrfTokenRepository,LazyCsrfTokenRepository
public interface CsrfTokenRepositoryAn API to allow changing the method in which the expectedCsrfTokenis associated to theHttpServletRequest. For example, it may be stored inHttpSession.- Since:
- 3.2
- See Also:
HttpSessionCsrfTokenRepository
-
-
Method Summary
All Methods Instance Methods Abstract Methods Default Methods Modifier and Type Method Description CsrfTokengenerateToken(javax.servlet.http.HttpServletRequest request)Generates aCsrfTokendefault DeferredCsrfTokenloadDeferredToken(javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response)Defers loading theCsrfTokenusing theHttpServletRequestandHttpServletResponseuntil it is needed by the application.CsrfTokenloadToken(javax.servlet.http.HttpServletRequest request)Loads the expectedCsrfTokenfrom theHttpServletRequestvoidsaveToken(CsrfToken token, javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response)
-
-
-
Method Detail
-
generateToken
CsrfToken generateToken(javax.servlet.http.HttpServletRequest request)
Generates aCsrfToken- Parameters:
request- theHttpServletRequestto use- Returns:
- the
CsrfTokenthat was generated. Cannot be null.
-
saveToken
void saveToken(CsrfToken token, javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response)
Saves theCsrfTokenusing theHttpServletRequestandHttpServletResponse. If theCsrfTokenis null, it is the same as deleting it.- Parameters:
token- theCsrfTokento save or null to deleterequest- theHttpServletRequestto useresponse- theHttpServletResponseto use
-
loadToken
CsrfToken loadToken(javax.servlet.http.HttpServletRequest request)
Loads the expectedCsrfTokenfrom theHttpServletRequest- Parameters:
request- theHttpServletRequestto use- Returns:
- the
CsrfTokenor null if none exists
-
loadDeferredToken
default DeferredCsrfToken loadDeferredToken(javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response)
Defers loading theCsrfTokenusing theHttpServletRequestandHttpServletResponseuntil it is needed by the application.The returned
DeferredCsrfTokenis cached to allow subsequent calls toDeferredCsrfToken.get()to return the sameCsrfTokenwithout the cost of loading or generating the token again.- Parameters:
request- theHttpServletRequestto useresponse- theHttpServletResponseto use- Returns:
- a
DeferredCsrfTokenthat will load theCsrfToken - Since:
- 5.8
-
-