[Esapi-user] CSRF JSF solutions

Eric Sheridan eric.sheridan at owasp.org
Mon Mar 21 20:22:36 EDT 2011


Chris - thanks for the heads up.

Sebastian - can you let me know what problems you had? I'm trying to
elevate CSRFGuard 3.0 to BETA, thus the need to eliminate bugs and
improve usability.

-Eric

On 3/21/11 6:57 PM, Chris Schmidt wrote:
> Hi Sebastian - I am curious as to what kinds of issues you encountered when
> trying to get CSRFGuard to work with JSF. I have also included Eric Sheridan
> on this email, the maintainer of the CSRFGuard project.
> 
> -----Original Message-----
> From: esapi-user-bounces at lists.owasp.org
> [mailto:esapi-user-bounces at lists.owasp.org] On Behalf Of Sebastian
> Sent: Monday, March 21, 2011 8:00 AM
> To: esapi-user at lists.owasp.org
> Subject: [Esapi-user] CSRF JSF solutions
> 
> Hi, some days ago i tried to configure CSRFGuard in a JSF proyect but i
> couldn't do it successfully. So i found another solution here
> http://blog.eisele.net/2011/02/preventing-csrf-with-jsf-20.html
> 
> It is much simpler than CSRFGuard, it hasn't advanced configuration options
> but it seems to works fine!!
> 
> Cheers,
> Sebastián
> _______________________________________________
> Esapi-user mailing list
> Esapi-user at lists.owasp.org
> https://lists.owasp.org/mailman/listinfo/esapi-user
> 



More information about the Esapi-user mailing list