Class AdminCsrfFilter
java.lang.Object
org.springframework.web.filter.GenericFilterBean
org.broadleafcommerce.common.security.handler.CsrfFilter
org.broadleafcommerce.openadmin.web.filter.AdminCsrfFilter
- All Implemented Interfaces:
jakarta.servlet.Filter,org.springframework.beans.factory.Aware,org.springframework.beans.factory.BeanNameAware,org.springframework.beans.factory.DisposableBean,org.springframework.beans.factory.InitializingBean,org.springframework.context.EnvironmentAware,org.springframework.core.env.EnvironmentCapable,org.springframework.web.context.ServletContextAware
@Deprecated
public class AdminCsrfFilter
extends org.broadleafcommerce.common.security.handler.CsrfFilter
Deprecated.
This class attempts the work flow of the CsrfFilter, but in the event of a Csrf token mismatch
(Session reset for example) the User will be redirected to login, if not session reset User is sent to previous location.
The "blCsrfFilter' from applicationContext-admin-security should reference this class (org.broadleafcommerce.openadmin.web.filter.AdminCsrfFilter)
instead of the CsrfFilter
- Author:
- trevorleffert
-
Field Summary
FieldsModifier and TypeFieldDescriptionprotected org.springframework.security.web.authentication.AuthenticationFailureHandlerDeprecated.Fields inherited from class org.broadleafcommerce.common.security.handler.CsrfFilter
excludedRequestPatterns, exploitProtectionService, LOGFields inherited from class org.springframework.web.filter.GenericFilterBean
logger -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoiddoFilter(jakarta.servlet.ServletRequest baseRequest, jakarta.servlet.ServletResponse baseResponse, jakarta.servlet.FilterChain chain) Deprecated.Methods inherited from class org.broadleafcommerce.common.security.handler.CsrfFilter
getExcludedRequestPatterns, setExcludedRequestPatternsMethods inherited from class org.springframework.web.filter.GenericFilterBean
addRequiredProperty, afterPropertiesSet, createEnvironment, destroy, getEnvironment, getFilterConfig, getFilterName, getServletContext, init, initBeanWrapper, initFilterBean, setBeanName, setEnvironment, setServletContext
-
Field Details
-
failureHandler
@Autowired @Qualifier("blAdminAuthenticationFailureHandler") protected org.springframework.security.web.authentication.AuthenticationFailureHandler failureHandlerDeprecated.
-
-
Constructor Details
-
AdminCsrfFilter
public AdminCsrfFilter()Deprecated.
-
-
Method Details
-
doFilter
public void doFilter(jakarta.servlet.ServletRequest baseRequest, jakarta.servlet.ServletResponse baseResponse, jakarta.servlet.FilterChain chain) throws IOException, jakarta.servlet.ServletException Deprecated.- Specified by:
doFilterin interfacejakarta.servlet.Filter- Overrides:
doFilterin classorg.broadleafcommerce.common.security.handler.CsrfFilter- Throws:
IOExceptionjakarta.servlet.ServletException
-
AdminSecurityFilterinstead