Re: CSRF prevention filter for REST

2015-10-26 Thread Violeta Georgieva
Hi,

2015-10-14 21:39 GMT+03:00 Violeta Georgieva :
>
> Hi,
>
> I would like to provide such a filter as part of the default Tomcat
filters [1].
> My plan is to extract the common functionality from the current
CsrfPreventionFIlter in a base class and then to use this functionality in
both CsrfPreventionFilter and the new filter which will be for REST.
> I will provide the functionality in trunk so that you will be able to
review it and give me a feedback.

I plan to back-port this feature in Tomcat 7/8.

Regards,
Violeta
>
> [1] http://marc.info/?t=13482586931=1=2


CSRF prevention filter for REST

2015-10-14 Thread Violeta Georgieva
Hi,

I would like to provide such a filter as part of the default Tomcat filters
[1].
My plan is to extract the common functionality from the current
CsrfPreventionFIlter in a base class and then to use this functionality in
both CsrfPreventionFilter and the new filter which will be for REST.
I will provide the functionality in trunk so that you will be able to
review it and give me a feedback.

Regards,
Violeta

[1] http://marc.info/?t=13482586931=1=2