@Component(value="blAdminCsrfFilter") public class AdminSecurityFilter extends SecurityFilter
StaleStateProtectionService for details.
applicationContext-admin-security should reference this class as follows:
...
<sec:custom-filter ref="blPreSecurityFilterChain" before="CHANNEL_FILTER"/>
<sec:custom-filter ref="blSecurityFilter" before="FORM_LOGIN_FILTER"/>
<sec:custom-filter ref="blAdminFilterSecurityInterceptor" after="EXCEPTION_TRANSLATION_FILTER"/>
<sec:custom-filter ref="blPostSecurityFilterChain" after="SWITCH_USER_FILTER"/>
</sec:http>
<bean id="blSecurityFilter" class="org.broadleafcommerce.openadmin.web.filter.AdminSecurityFilter" />
...
| Modifier and Type | Field and Description |
|---|---|
protected org.springframework.security.web.authentication.AuthenticationFailureHandler |
failureHandler |
excludedRequestPatterns, exploitProtectionService, staleStateProtectionService| Constructor and Description |
|---|
AdminSecurityFilter() |
| Modifier and Type | Method and Description |
|---|---|
void |
doFilterInternal(javax.servlet.http.HttpServletRequest baseRequest,
javax.servlet.http.HttpServletResponse baseResponse,
javax.servlet.FilterChain chain) |
getExcludedRequestPatterns, setExcludedRequestPatternsdoFilter, getAlreadyFilteredAttributeName, isAsyncDispatch, isAsyncStarted, shouldNotFilter, shouldNotFilterAsyncDispatch, shouldNotFilterErrorDispatch@Autowired(required=false) @Qualifier(value="blAdminAuthenticationFailureHandler") protected org.springframework.security.web.authentication.AuthenticationFailureHandler failureHandler
public void doFilterInternal(javax.servlet.http.HttpServletRequest baseRequest,
javax.servlet.http.HttpServletResponse baseResponse,
javax.servlet.FilterChain chain)
throws IOException,
javax.servlet.ServletException
doFilterInternal in class SecurityFilterIOExceptionjavax.servlet.ServletExceptionCopyright © 2018. All rights reserved.