1 package org.cacert.gigi.output;
3 import java.io.PrintWriter;
6 import javax.servlet.ServletRequest;
7 import javax.servlet.http.HttpServletRequest;
9 import org.cacert.gigi.Language;
10 import org.cacert.gigi.pages.Page;
11 import org.cacert.gigi.util.RandomToken;
13 public abstract class Form implements Outputable {
16 csrf = RandomToken.generateToken(32);
19 public abstract boolean submit(PrintWriter out, HttpServletRequest req);
21 public final void output(PrintWriter out, Language l,
22 Map<String, Object> vars) {
23 out.println("<form method='POST' autocomplete='off'>");
24 outputContent(out, l, vars);
25 out.print("<input type='csrf' value='");
26 out.print(getCSRFToken());
27 out.println("'></form>");
30 protected abstract void outputContent(PrintWriter out, Language l,
31 Map<String, Object> vars);
33 protected void outputError(PrintWriter out, ServletRequest req, String text) {
35 out.print(Page.translate(req, text));
36 out.println("</div>");
39 protected String getCSRFToken() {
42 protected void checkCSRF(HttpServletRequest req) {
43 if (!csrf.equals(req.getParameter("csrf"))) {
44 throw new CSRFError();
48 public class CSRFError extends Error {