Browse Source

Prevent CSRF token leaks in server logs

Signed-off-by: Pekka Helenius <fincer89@hotmail.com>
v0.0.4-alpha
Pekka Helenius 4 years ago
parent
commit
5ba4227c1e
1 changed files with 6 additions and 0 deletions
  1. +6
    -0
      bookstore/src/main/java/com/fjordtek/bookstore/service/HttpServerLogger.java

+ 6
- 0
bookstore/src/main/java/com/fjordtek/bookstore/service/HttpServerLogger.java View File

@ -43,6 +43,12 @@ public class HttpServerLogger {
while (requestParamNames.hasMoreElements()) {
String paramName = requestParamNames.nextElement().toString();
/*
* Do not log CSRF tokens
*/
if (paramName.contains("csrf")) continue;
String[] paramValues = request.getParameterValues(paramName);
requestParams.add(


Loading…
Cancel
Save