Class HttpHeaderSecurityFilter
java.lang.Object
org.apache.catalina.filters.FilterBase
org.apache.catalina.filters.HttpHeaderSecurityFilter
- All Implemented Interfaces:
Filter
Provides a single configuration point for security measures that required the addition of one or more HTTP headers to
the response.
-
Field Summary
Fields inherited from class FilterBase
sm -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoiddoFilter(ServletRequest request, ServletResponse response, FilterChain chain) ThedoFiltermethod of the Filter is called by the container each time a request/response pair is passed through the chain due to a client request for a resource at the end of the chain.Returns the X-Frame-Options value.Returns the URI used with the ALLOW_FROM X-Frame-Options directive.intReturns the maximum age in seconds for the HSTS header.protected LogReturns the logger for this filter.voidinit(FilterConfig filterConfig) Iterates over the configuration parameters and either logs a warning, or throws an exception for any parameter that does not have a matching setter in this filter.booleanReturns whether anti-click-jacking protection is enabled.booleanReturns whether content type sniffing protection is enabled.protected booleanDetermines if an exception when calling a setter or an unknown configuration attribute triggers the failure of this filter which in turn will prevent the web application from starting.booleanReturns whether HSTS is enabled.booleanReturns whether subdomains are included in the HSTS header.booleanReturns whether the preload directive is included in the HSTS header.booleanDeprecated.voidsetAntiClickJackingEnabled(boolean antiClickJackingEnabled) Enables or disables anti-click-jacking protection.voidsetAntiClickJackingOption(String antiClickJackingOption) Sets the X-Frame-Options value for click-jacking protection.voidsetAntiClickJackingUri(String antiClickJackingUri) Sets the URI used with the ALLOW_FROM X-Frame-Options directive.voidsetBlockContentTypeSniffingEnabled(boolean blockContentTypeSniffingEnabled) Enables or disables content type sniffing protection.voidsetHstsEnabled(boolean hstsEnabled) Enables or disables HSTS.voidsetHstsIncludeSubDomains(boolean hstsIncludeSubDomains) Sets whether subdomains should be included in the HSTS header.voidsetHstsMaxAgeSeconds(int hstsMaxAgeSeconds) Sets the maximum age in seconds for the HSTS header.voidsetHstsPreload(boolean hstsPreload) Sets whether the preload directive should be included in the HSTS header.voidsetXssProtectionEnabled(boolean xssProtectionEnabled) Deprecated.
-
Constructor Details
-
HttpHeaderSecurityFilter
public HttpHeaderSecurityFilter()Creates a new instance of the filter.
-
-
Method Details
-
init
Description copied from class:FilterBaseIterates over the configuration parameters and either logs a warning, or throws an exception for any parameter that does not have a matching setter in this filter.- Specified by:
initin interfaceFilter- Overrides:
initin classFilterBase- Parameters:
filterConfig- The configuration information associated with the filter instance being initialised- Throws:
ServletException- ifFilterBase.isConfigProblemFatal()returnstrueand a configured parameter does not have a matching setter
-
doFilter
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException Description copied from interface:jakarta.servlet.FilterThedoFiltermethod of the Filter is called by the container each time a request/response pair is passed through the chain due to a client request for a resource at the end of the chain. The FilterChain passed in to this method allows the Filter to pass on the request and response to the next entity in the chain.A typical implementation of this method would follow the following pattern:-
1. Examine the request
2. Optionally wrap the request object with a custom implementation to filter content or headers for input filtering
3. Optionally wrap the response object with a custom implementation to filter content or headers for output filtering
4. a) Either invoke the next entity in the chain using the FilterChain object (chain.doFilter()),
4. b) or not pass on the request/response pair to the next entity in the filter chain to block the request processing
5. Directly set headers on the response after invocation of the next entity in the filter chain.- Parameters:
request- The request to processresponse- The response associated with the requestchain- Provides access to the next filter in the chain for this filter to pass the request and response to for further processing- Throws:
IOException- if an I/O error occurs during this filter's processing of the requestServletException- if the processing fails for any other reason
-
getLogger
Description copied from class:FilterBaseReturns the logger for this filter.- Specified by:
getLoggerin classFilterBase- Returns:
- the logger
-
isConfigProblemFatal
protected boolean isConfigProblemFatal()Description copied from class:FilterBaseDetermines if an exception when calling a setter or an unknown configuration attribute triggers the failure of this filter which in turn will prevent the web application from starting.- Overrides:
isConfigProblemFatalin classFilterBase- Returns:
trueif a problem should trigger the failure of this filter, elsefalse
-
isHstsEnabled
public boolean isHstsEnabled()Returns whether HSTS is enabled.- Returns:
trueif HSTS is enabled
-
setHstsEnabled
public void setHstsEnabled(boolean hstsEnabled) Enables or disables HSTS.- Parameters:
hstsEnabled-trueto enable HSTS
-
getHstsMaxAgeSeconds
public int getHstsMaxAgeSeconds()Returns the maximum age in seconds for the HSTS header.- Returns:
- the maximum age in seconds
-
setHstsMaxAgeSeconds
public void setHstsMaxAgeSeconds(int hstsMaxAgeSeconds) Sets the maximum age in seconds for the HSTS header.- Parameters:
hstsMaxAgeSeconds- the maximum age in seconds
-
isHstsIncludeSubDomains
public boolean isHstsIncludeSubDomains()Returns whether subdomains are included in the HSTS header.- Returns:
trueif subdomains are included
-
setHstsIncludeSubDomains
public void setHstsIncludeSubDomains(boolean hstsIncludeSubDomains) Sets whether subdomains should be included in the HSTS header.- Parameters:
hstsIncludeSubDomains-trueto include subdomains
-
isHstsPreload
public boolean isHstsPreload()Returns whether the preload directive is included in the HSTS header.- Returns:
trueif preload is enabled
-
setHstsPreload
public void setHstsPreload(boolean hstsPreload) Sets whether the preload directive should be included in the HSTS header.- Parameters:
hstsPreload-trueto include preload
-
isAntiClickJackingEnabled
public boolean isAntiClickJackingEnabled()Returns whether anti-click-jacking protection is enabled.- Returns:
trueif anti-click-jacking is enabled
-
setAntiClickJackingEnabled
public void setAntiClickJackingEnabled(boolean antiClickJackingEnabled) Enables or disables anti-click-jacking protection.- Parameters:
antiClickJackingEnabled-trueto enable anti-click-jacking
-
getAntiClickJackingOption
Returns the X-Frame-Options value.- Returns:
- the X-Frame-Options value
-
setAntiClickJackingOption
Sets the X-Frame-Options value for click-jacking protection.- Parameters:
antiClickJackingOption- the X-Frame-Options value (DENY, SAMEORIGIN, or ALLOW-FROM)
-
getAntiClickJackingUri
Returns the URI used with the ALLOW_FROM X-Frame-Options directive.- Returns:
- the ALLOW_FROM URI
-
isBlockContentTypeSniffingEnabled
public boolean isBlockContentTypeSniffingEnabled()Returns whether content type sniffing protection is enabled.- Returns:
trueif content type sniffing protection is enabled
-
setBlockContentTypeSniffingEnabled
public void setBlockContentTypeSniffingEnabled(boolean blockContentTypeSniffingEnabled) Enables or disables content type sniffing protection.- Parameters:
blockContentTypeSniffingEnabled-trueto enable protection
-
setAntiClickJackingUri
Sets the URI used with the ALLOW_FROM X-Frame-Options directive.- Parameters:
antiClickJackingUri- the URI for ALLOW_FROM
-
isXssProtectionEnabled
Deprecated. -
setXssProtectionEnabled
Deprecated.
-