Book Image

Spring 5.0 Cookbook

By : Sherwin John C. Tragura
Book Image

Spring 5.0 Cookbook

By: Sherwin John C. Tragura

Overview of this book

The Spring framework has been the go-to framework for Java developers for quite some time. It enhances modularity, provides more readable code, and enables the developer to focus on developing the application while the underlying framework takes care of transaction APIs, remote APIs, JMX APIs, and JMS APIs. The upcoming version of the Spring Framework has a lot to offer, above and beyond the platform upgrade to Java 9, and this book will show you all you need to know to overcome common to advanced problems you might face. Each recipe will showcase some old and new issues and solutions, right from configuring Spring 5.0 container to testing its components. Most importantly, the book will highlight concurrent processes, asynchronous MVC and reactive programming using Reactor Core APIs. Aside from the core components, this book will also include integration of third-party technologies that are mostly needed in building enterprise applications. By the end of the book, the reader will not only be well versed with the essential concepts of Spring, but will also have mastered its latest features in a solution-oriented manner.
Table of Contents (20 chapters)
Title Page
Credits
About the Author
About the Reviewer
www.PacktPub.com
Customer Feedback
Preface

Solving Cross-Site Request Forgery (CSRF) and session fixation attacks


CSRF occurs when a user who is currently logged in has accidentally processed an unknown link or event which tries to execute a valid transaction using suspicious request parameters, which may lead to some disastrous and catastrophic effects to the database, network, or even to the system infrastructure. On the other hand, session fixation happens when a user accidentally leaves his session open after logging out, and through this idle session an exploit happens because someone maliciously uses the existing session ID and variables to execute unwanted transactions. Invalidating sessions does not guarantee a solution to session fixation attacks; thus, this recipe will explain how Spring Security can protect Spring MVC applications from these two vulnerabilities.

Getting started

The same ch04 project will be used to execute a security model which gives us the best and immediate solutions for preventing CSRF and session fixation...