Class CsrfChannelInterceptor

java.lang.Object
org.springframework.security.messaging.web.csrf.CsrfChannelInterceptor
All Implemented Interfaces:
org.springframework.messaging.support.ChannelInterceptor

public final class CsrfChannelInterceptor extends Object implements org.springframework.messaging.support.ChannelInterceptor
ChannelInterceptor that validates that a valid CSRF is included in the header of any SimpMessageType.CONNECT message. The expected CsrfToken is populated by CsrfTokenHandshakeInterceptor.
Since:
4.0
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    org.springframework.messaging.Message<?>
    preSend(org.springframework.messaging.Message<?> message, org.springframework.messaging.MessageChannel channel)
     

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait

    Methods inherited from interface org.springframework.messaging.support.ChannelInterceptor

    afterReceiveCompletion, afterSendCompletion, postReceive, postSend, preReceive
  • Constructor Details

    • CsrfChannelInterceptor

      public CsrfChannelInterceptor()
  • Method Details

    • preSend

      public org.springframework.messaging.Message<?> preSend(org.springframework.messaging.Message<?> message, org.springframework.messaging.MessageChannel channel)
      Specified by:
      preSend in interface org.springframework.messaging.support.ChannelInterceptor