All Downloads are FREE. Search and download functionalities are using the official Maven repository.

org.owasp.csrfguard.session.LogicalSession Maven / Gradle / Ivy

Go to download

OWASP CSRFGuard is a library that implements a variant of the synchronizer token pattern to mitigate the risk of Cross-Site Request Forgery (CSRF) attacks.

The newest version!
/*
 * The OWASP CSRFGuard Project, BSD License
 * Copyright (c) 2011, Eric Sheridan ([email protected])
 * All rights reserved.
 *
 * Redistribution and use in source and binary forms, with or without
 * modification, are permitted provided that the following conditions are met:
 *
 *     1. Redistributions of source code must retain the above copyright notice,
 *        this list of conditions and the following disclaimer.
 *     2. Redistributions in binary form must reproduce the above copyright
 *        notice, this list of conditions and the following disclaimer in the
 *        documentation and/or other materials provided with the distribution.
 *     3. Neither the name of OWASP nor the names of its contributors may be used
 *        to endorse or promote products derived from this software without specific
 *        prior written permission.
 *
 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
 * ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
 */
package org.owasp.csrfguard.session;

import jakarta.servlet.http.HttpSession;

/**
 * Represents a logical session that enables decoupling from the container's session implementation in case the client application uses a stateless approach (e.g. token based authentication)
 */
public interface LogicalSession {

    /**
     * Returns the logical session key
     * @return identifier that uniquely identifies the current actor
     */
    String getKey();

    /**
     * Returns true if the client does not yet know about the
     * session or if the client chooses not to join the session.
     *
     * @see jakarta.servlet.http.HttpSession#isNew()
     *
     * @return true if the server has created a session, but the client has not yet joined
     */
    boolean isNew();

    /**
     * Invalidates this session then unbinds any objects bound to it.
     */
    void invalidate();

    /**
     * @return whether the objects were generated or not.
     */
    boolean areTokensGenerated();

    /**
     * Set whether the objects were generated or not.
     *
     * @param areTokensGenerated set true if the tokens were generated, false otherwise
     */
    void setTokensGenerated(boolean areTokensGenerated);

    /**
     * Saves an object to the current session
     *
     * @see HttpSession#setAttribute(java.lang.String, java.lang.Object)
     *
     * @param attribute the name to which the object is bound; cannot be null
     * @param value the object to be bound
     */
    void setAttribute(final String attribute, final Object value);

    /**
     * Retrieves an object from the session using its name
     *
     * @see HttpSession#getAttribute(String)
     *
     * @param attributeName - identifies a certain object on the session
     * @return the object associated to the attribute name
     */
    Object getAttribute(String attributeName);
}




© 2015 - 2024 Weber Informatics LLC | Privacy Policy