1 package org.cacert.gigi.output;
3 import java.io.PrintWriter;
6 import javax.servlet.ServletRequest;
7 import javax.servlet.http.HttpServletRequest;
8 import javax.servlet.http.HttpSession;
10 import org.cacert.gigi.Language;
11 import org.cacert.gigi.pages.Page;
12 import org.cacert.gigi.util.RandomToken;
14 public abstract class Form implements Outputable {
17 public Form(HttpServletRequest hsr) {
18 csrf = RandomToken.generateToken(32);
19 HttpSession hs = hsr.getSession();
20 hs.setAttribute("form/" + getClass().getName() + "/" + csrf, this);
24 public abstract boolean submit(PrintWriter out, HttpServletRequest req);
27 public final void output(PrintWriter out, Language l, Map<String, Object> vars) {
28 out.println("<form method='POST' autocomplete='off'>");
29 outputContent(out, l, vars);
30 out.print("<input type='hidden' name='csrf' value='");
31 out.print(getCSRFToken());
32 out.println("'></form>");
35 protected abstract void outputContent(PrintWriter out, Language l, Map<String, Object> vars);
37 protected void outputError(PrintWriter out, ServletRequest req, String text) {
39 out.print(Page.translate(req, text));
40 out.println("</div>");
43 protected String getCSRFToken() {
47 protected void checkCSRF(HttpServletRequest req) {
48 if (!csrf.equals(req.getParameter("csrf"))) {
49 throw new CSRFError();
53 public static <T extends Form> T getForm(HttpServletRequest req, Class<T> target) {
54 String csrf = req.getParameter("csrf");
56 throw new CSRFError();
58 HttpSession hs = req.getSession();
60 throw new CSRFError();
62 Form f = (Form) hs.getAttribute("form/" + target.getName() + "/" + csrf);
64 throw new CSRFError();
69 public static class CSRFError extends Error {