Browse Source
* Move DeferredCsrfToken to top-level and implement Supplier<CsrfToken> * Move RepositoryDeferredCsrfToken to top-level and make package-private * Add CsrfTokenRepository.loadToken(HttpServletRequest, HttpServletResponse) * Update CsrfFilter * Rename CsrfTokenRepositoryRequestHandler to CsrfTokenRequestAttributeHandler Issue gh-11892 Closes gh-11918pull/11961/head
31 changed files with 533 additions and 350 deletions
@ -0,0 +1,74 @@
@@ -0,0 +1,74 @@
|
||||
/* |
||||
* Copyright 2002-2016 the original author or authors. |
||||
* |
||||
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
* you may not use this file except in compliance with the License. |
||||
* You may obtain a copy of the License at |
||||
* |
||||
* https://www.apache.org/licenses/LICENSE-2.0
|
||||
* |
||||
* Unless required by applicable law or agreed to in writing, software |
||||
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
* See the License for the specific language governing permissions and |
||||
* limitations under the License. |
||||
*/ |
||||
|
||||
package org.springframework.security.test.web.servlet.request; |
||||
|
||||
import org.junit.jupiter.api.Test; |
||||
import org.junit.jupiter.api.extension.ExtendWith; |
||||
|
||||
import org.springframework.beans.factory.annotation.Autowired; |
||||
import org.springframework.mock.web.MockHttpServletRequest; |
||||
import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
||||
import org.springframework.security.config.annotation.web.builders.WebSecurity; |
||||
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; |
||||
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; |
||||
import org.springframework.security.test.web.support.WebTestUtils; |
||||
import org.springframework.security.web.csrf.CookieCsrfTokenRepository; |
||||
import org.springframework.security.web.csrf.CsrfTokenRepository; |
||||
import org.springframework.test.context.ContextConfiguration; |
||||
import org.springframework.test.context.junit.jupiter.SpringExtension; |
||||
import org.springframework.test.context.web.WebAppConfiguration; |
||||
import org.springframework.web.context.WebApplicationContext; |
||||
|
||||
import static org.assertj.core.api.Assertions.assertThat; |
||||
import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.post; |
||||
|
||||
@ExtendWith(SpringExtension.class) |
||||
@ContextConfiguration |
||||
@WebAppConfiguration |
||||
public class SecurityMockMvcRequestPostProcessorsCsrfDebugFilterTests { |
||||
|
||||
@Autowired |
||||
private WebApplicationContext wac; |
||||
|
||||
// SEC-3836
|
||||
@Test |
||||
public void findCookieCsrfTokenRepository() { |
||||
MockHttpServletRequest request = post("/").buildRequest(this.wac.getServletContext()); |
||||
CsrfTokenRepository csrfTokenRepository = WebTestUtils.getCsrfTokenRepository(request); |
||||
assertThat(csrfTokenRepository).isNotNull(); |
||||
assertThat(csrfTokenRepository).isEqualTo(Config.cookieCsrfTokenRepository); |
||||
} |
||||
|
||||
@EnableWebSecurity |
||||
static class Config extends WebSecurityConfigurerAdapter { |
||||
|
||||
static CsrfTokenRepository cookieCsrfTokenRepository = new CookieCsrfTokenRepository(); |
||||
|
||||
@Override |
||||
protected void configure(HttpSecurity http) throws Exception { |
||||
http.csrf().csrfTokenRepository(cookieCsrfTokenRepository); |
||||
} |
||||
|
||||
@Override |
||||
public void configure(WebSecurity web) { |
||||
// Enable the DebugFilter
|
||||
web.debug(true); |
||||
} |
||||
|
||||
} |
||||
|
||||
} |
||||
@ -0,0 +1,71 @@
@@ -0,0 +1,71 @@
|
||||
/* |
||||
* Copyright 2002-2022 the original author or authors. |
||||
* |
||||
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
* you may not use this file except in compliance with the License. |
||||
* You may obtain a copy of the License at |
||||
* |
||||
* https://www.apache.org/licenses/LICENSE-2.0
|
||||
* |
||||
* Unless required by applicable law or agreed to in writing, software |
||||
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
* See the License for the specific language governing permissions and |
||||
* limitations under the License. |
||||
*/ |
||||
|
||||
package org.springframework.security.web.csrf; |
||||
|
||||
import javax.servlet.http.HttpServletRequest; |
||||
import javax.servlet.http.HttpServletResponse; |
||||
|
||||
/** |
||||
* @author Rob Winch |
||||
* @author Steve Riesenberg |
||||
* @since 5.8 |
||||
*/ |
||||
final class RepositoryDeferredCsrfToken implements DeferredCsrfToken { |
||||
|
||||
private final CsrfTokenRepository csrfTokenRepository; |
||||
|
||||
private final HttpServletRequest request; |
||||
|
||||
private final HttpServletResponse response; |
||||
|
||||
private CsrfToken csrfToken; |
||||
|
||||
private boolean missingToken; |
||||
|
||||
RepositoryDeferredCsrfToken(CsrfTokenRepository csrfTokenRepository, HttpServletRequest request, |
||||
HttpServletResponse response) { |
||||
this.csrfTokenRepository = csrfTokenRepository; |
||||
this.request = request; |
||||
this.response = response; |
||||
} |
||||
|
||||
@Override |
||||
public CsrfToken get() { |
||||
init(); |
||||
return this.csrfToken; |
||||
} |
||||
|
||||
@Override |
||||
public boolean isGenerated() { |
||||
init(); |
||||
return this.missingToken; |
||||
} |
||||
|
||||
private void init() { |
||||
if (this.csrfToken != null) { |
||||
return; |
||||
} |
||||
|
||||
this.csrfToken = this.csrfTokenRepository.loadToken(this.request); |
||||
this.missingToken = (this.csrfToken == null); |
||||
if (this.missingToken) { |
||||
this.csrfToken = this.csrfTokenRepository.generateToken(this.request); |
||||
this.csrfTokenRepository.saveToken(this.csrfToken, this.request, this.response); |
||||
} |
||||
} |
||||
|
||||
} |
||||
@ -0,0 +1,40 @@
@@ -0,0 +1,40 @@
|
||||
/* |
||||
* Copyright 2002-2022 the original author or authors. |
||||
* |
||||
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
* you may not use this file except in compliance with the License. |
||||
* You may obtain a copy of the License at |
||||
* |
||||
* https://www.apache.org/licenses/LICENSE-2.0
|
||||
* |
||||
* Unless required by applicable law or agreed to in writing, software |
||||
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
* See the License for the specific language governing permissions and |
||||
* limitations under the License. |
||||
*/ |
||||
|
||||
package org.springframework.security.web.csrf; |
||||
|
||||
final class TestDeferredCsrfToken implements DeferredCsrfToken { |
||||
|
||||
private final CsrfToken csrfToken; |
||||
|
||||
private final boolean isGenerated; |
||||
|
||||
TestDeferredCsrfToken(CsrfToken csrfToken, boolean isGenerated) { |
||||
this.csrfToken = csrfToken; |
||||
this.isGenerated = isGenerated; |
||||
} |
||||
|
||||
@Override |
||||
public CsrfToken get() { |
||||
return this.csrfToken; |
||||
} |
||||
|
||||
@Override |
||||
public boolean isGenerated() { |
||||
return this.isGenerated; |
||||
} |
||||
|
||||
} |
||||
Loading…
Reference in new issue