[Owasp-csrfguard] Configuration properties for JSF Primefaces

douxc at voila.fr douxc at voila.fr
Fri Mar 13 15:43:12 UTC 2015


Hello,
i'm trying to configure my project with csfguard, but the first page of my site redirect directly with the error page configured in the prioperties file. The technology used for the GUI is JSF Primefaces 5. 
My config is :

org.owasp.csrfguard.Logger=org.owasp.csrfguard.log.ConsoleLogger
#org.owasp.csrfguard.NewTokenLandingPage=
org.owasp.csrfguard.ValidateWhenNoSessionExists = true

org.owasp.csrfguard.TokenPerPage=true
org.owasp.csrfguard.Rotate=false
org.owasp.csrfguard.Ajax=true
org.owasp.csrfguard.action.class.Redirect=org.owasp.csrfguard.actions.Redirect
org.owasp.csrfguard.action.Redirect.ErrorPage=/error.html
org.owasp.csrfguard.SessionKey=OWASP_CSRFTOKEN
org.owaorg.owasp.csrfguard.TokenLength=32
org.owasp.csrfguard.PRNG=SHA1PRNG
org.owasp.csrfguard.unprotected.Index=/RootContext/index.xhtml
org.owasp.csrfguard.unprotected.Default=/RootContext/

I tried several options but did'nt manage yet to prevent the application from redirecting to error page. The technology uses Ajax and javascript and JSF 2 servlet.

Could someone help me ?

Thanks a lot,

best regards

___________________________________________________________
Mode, hifi, maison,… J'achète malin. Je compare les prix avec Voila.fr http://shopping.voila.fr/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.owasp.org/pipermail/owasp-csrfguard/attachments/20150313/75b6a5d8/attachment.html>


More information about the Owasp-csrfguard mailing list