public abstract class Form implements Outputable {
String csrf;
+
public Form() {
csrf = RandomToken.generateToken(32);
}
public abstract boolean submit(PrintWriter out, HttpServletRequest req);
+
@Override
- public final void output(PrintWriter out, Language l,
- Map<String, Object> vars) {
+ public final void output(PrintWriter out, Language l, Map<String, Object> vars) {
out.println("<form method='POST' autocomplete='off'>");
outputContent(out, l, vars);
out.print("<input type='csrf' value='");
out.println("'></form>");
}
- protected abstract void outputContent(PrintWriter out, Language l,
- Map<String, Object> vars);
+ protected abstract void outputContent(PrintWriter out, Language l, Map<String, Object> vars);
protected void outputError(PrintWriter out, ServletRequest req, String text) {
out.print("<div>");
protected String getCSRFToken() {
return csrf;
}
+
protected void checkCSRF(HttpServletRequest req) {
if (!csrf.equals(req.getParameter("csrf"))) {
throw new CSRFError();