csrf

package
v2.3.2+incompatible Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2017 License: Apache-2.0 Imports: 5 Imported by: 50

Documentation

Index

Constants

View Source
const (
	// CookieName is a name of the cookie
	CookieName = "grv_csrf"
	// HeaderName is the default HTTP request header to inspect
	HeaderName = "X-CSRF-Token"
)

Variables

This section is empty.

Functions

func AddCSRFProtection

func AddCSRFProtection(w http.ResponseWriter, r *http.Request) (string, error)

AddCSRFProtection adds CSRF token into the user session via secure cookie, it implements "double submit cookie" approach to check against CSRF attacks https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29_Prevention_Cheat_Sheet#Double_Submit_Cookie

func VerifyToken

func VerifyToken(w http.ResponseWriter, r *http.Request) error

VerifyToken checks if the cookie value and request value match.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL