How to provide protection against Cross Site Request Forgery (CSRF) attacks for an old web application built on Java and struts2 framework?

Tried adding filter before servlet, stuck over there.

1

There are 1 best solutions below

0
Roman C On

Old application should use a token or tokenSession interceptor.

You can find details in my previous answer: Struts2 token interceptor: CSRF protection.