Uploaded image for project: 'Shiro'
  1. Shiro
  2. SHIRO-31

Add support for easy protection against CSRF attacks

Attach filesAttach ScreenshotAdd voteVotersWatch issueWatchersLinkUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • None
    • None
    • None
    • None

    Description

      I have raised a similar issue for the Grails plugin here:

      http://jira.codehaus.org/browse/GRAILSPLUGINS-806

      I'm not sure what form the implementation should take, but it's worth taking a look at the information provided by OWASP:

      http://www.owasp.org/index.php/Top_10_2007-A5

      I'm considering adding a <jsec:form> tag that automatically adds a generated token that can be checked by the JSecurity filter on form submission.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            pledbrook Peter Ledbrook

            Dates

              Created:
              Updated:

              Slack

                Issue deployment