aspose file tools*
The moose likes Servlets and the fly likes Cross Site Request Forgery Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login


Win a copy of Soft Skills this week in the Jobs Discussion forum!
JavaRanch » Java Forums » Java » Servlets
Bookmark "Cross Site Request Forgery" Watch "Cross Site Request Forgery" New topic
Author

Cross Site Request Forgery

Parminder Dhillon
Greenhorn

Joined: Dec 19, 2007
Posts: 5
Hi

I am using owasp cross site request forgery guard(CSRFGuard) in one of my web based application.But its implementation is not proper in many pages where i use sendReditect means i redirect application to other page and alson in those pages where i use window.open or window.location

Thanks
Parminder
David O'Meara
Rancher

Joined: Mar 06, 2001
Posts: 13459

Do you have a question?
Parminder Dhillon
Greenhorn

Joined: Dec 19, 2007
Posts: 5
Yes my qustion is what to do in that case when redirecting to other page and we are using Cross site Request forger guard.As my application gives error in that case.
Jeanne Boyarsky
author & internet detective
Marshal

Joined: May 26, 2003
Posts: 31057
    
232

Originally posted by Parminder Dhillon:
where i use window.open or window.location

It's an open source filter. You can add to the code to include looking for javascript actions/urls and add the token that way.


[Blog] [JavaRanch FAQ] [How To Ask Questions The Smart Way] [Book Promos]
Blogging on Certs: SCEA Part 1, Part 2 & 3, Core Spring 3, OCAJP, OCPJP beta, TOGAF part 1 and part 2
 
I agree. Here's the link: http://aspose.com/file-tools
 
subject: Cross Site Request Forgery