isapir commented on code in PR #681: URL: https://github.com/apache/tomcat/pull/681#discussion_r1430457497
########## java/org/apache/catalina/filters/CsrfPreventionFilter.java: ########## @@ -53,6 +58,25 @@ public class CsrfPreventionFilter extends CsrfPreventionFilterBase { private String nonceRequestParameterName = Constants.CSRF_NONCE_REQUEST_PARAM; + private boolean enforce = true; + + private Collection<Predicate<String>> noNoncePatterns = DEFAULT_NO_NONCE_URL_PATTERNS; + + private static final Collection<Predicate<String>> DEFAULT_NO_NONCE_URL_PATTERNS; Review Comment: I had to read these two lines a couple of times. Can you move line 65 to be before line 63? It will make the code easier to read IMO, in the sense that first you declare a field and only afterwards you use it -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org