While implementing CSRF for JForum, I needed to extend the OWASP solution. Let me tell you, they don’t make it easy to extend. Lots of final. Here’s what I did – linked to code on github. To read about the original problem or why I choose the OWASP filter, see part 1. Extending the OWASP [...]
↧