Index: lams_central/conf/security/Owasp.CsrfGuard.properties =================================================================== diff -u -r7a9dcf2073f058bd353c8423c8bc732f0d006b44 -r71601beccc7097451a521af6ccf11139f5b6b0c5 --- lams_central/conf/security/Owasp.CsrfGuard.properties (.../Owasp.CsrfGuard.properties) (revision 7a9dcf2073f058bd353c8423c8bc732f0d006b44) +++ lams_central/conf/security/Owasp.CsrfGuard.properties (.../Owasp.CsrfGuard.properties) (revision 71601beccc7097451a521af6ccf11139f5b6b0c5) @@ -10,29 +10,74 @@ org.owasp.csrfguard.protected.assessmentDefineLater=/lams/tool/laasse10/authoring/definelater.do org.owasp.csrfguard.protected.assessmentSubmissionDeadline=/lams/tool/laasse10/monitoring/setSubmissionDeadline.do + +org.owasp.csrfguard.protected.chatDefineLater=/lams/tool/lachat11/authoring/definelater.do org.owasp.csrfguard.protected.chatSubmissionDeadline=/lams/tool/lachat11/monitoring/setSubmissionDeadline.do + +org.owasp.csrfguard.protected.dacoDefineLater=/lams/tool/ladaco10/authoring/definelater.do +org.owasp.csrfguard.protected.dokuDefineLater=/lams/tool/ladoku11/authoring/definelater.do + +org.owasp.csrfguard.protected.forumDefineLater=/lams/tool/lafrum11/authoring/definelater.do org.owasp.csrfguard.protected.forumAuthoringSave=/lams/tool/lafrum11/authoring/update.do org.owasp.csrfguard.protected.forumSubmissionDeadline=/lams/tool/lafrum11/monitoring/setSubmissionDeadline.do org.owasp.csrfguard.protected.forumUpdateMark=/lams/tool/lafrum11/monitoring/updateMark.do -org.owasp.csrfguard.protected.imageUpdateImage=/lams/tool/laimag10/monitoring/updateImage.do -org.owasp.csrfguard.protected.imageSaveNewImage=/lams/tool/laimag10/learning/saveNewImage.do -org.owasp.csrfguard.protected.imageToggleVisibility=/lams/tool/laimag10/monitoring/toggleImageVisibility.do + +org.owasp.csrfguard.protected.imagesDefineLater=/lams/tool/laimag10/authoring/definelater.do +org.owasp.csrfguard.protected.imagesSaveNewImage=/lams/tool/laimag10/learning/saveNewImage.do +org.owasp.csrfguard.protected.imagesToggleVisibility=/lams/tool/laimag10/monitoring/toggleImageVisibility.do +org.owasp.csrfguard.protected.imagesUpdateImage=/lams/tool/laimag10/monitoring/updateImage.do + +org.owasp.csrfguard.protected.imsccDefineLater=/lams/tool/laimsc11/authoring/definelater.do + +org.owasp.csrfguard.protected.lamcDefineLater=/lams/tool/lamc11/authoring/definelater.do org.owasp.csrfguard.protected.lamcSubmissionDeadline=/lams/tool/lamc11/monitoring/setSubmissionDeadline.do org.owasp.csrfguard.protected.lamcSaveUserMark=/lams/tool/lamc11/monitoring/saveUserMark.do + org.owasp.csrfguard.protected.leaderSaveLeaders=/lams/tool/lalead11/monitoring/saveLeaders.do + +org.owasp.csrfguard.protected.laqaDefineLater=/lams/tool/laqa11/authoring/definelater.do org.owasp.csrfguard.protected.laqaSubmissionDeadline=/lams/tool/laqa11/monitoring/setSubmissionDeadline.do + +org.owasp.csrfguard.protected.larsrcDefineLater=/lams/tool/larsrc11/authoring/definelater.do +org.owasp.csrfguard.protected.larsrcChangeItemVisibility=/lams/tool/larsrc11/monitoring/changeItemVisibility.do + +org.owasp.csrfguard.protected.leaderDefineLater=/lams/tool/lalead11/authoring/definelater.do + +org.owasp.csrfguard.protected.mindmapDefineLater=/lams/tool/lamind10/authoring/definelater.do org.owasp.csrfguard.protected.mindmapSubmissionDeadline=/lams/tool/lamind10/monitoring/setSubmissionDeadline.do + +org.owasp.csrfguard.protected.nbDefineLater=/lams/tool/lanb11/authoring/definelater.do +org.owasp.csrfguard.protected.notebookDefineLater=/lams/tool/lantbk11/authoring/definelater.do org.owasp.csrfguard.protected.notebookSubmissionDeadline=/lams/tool/lantbk11/monitoring/setSubmissionDeadline.do org.owasp.csrfguard.protected.notebookSaveTeacherComment=/lams/tool/lantbk11/monitoring/saveTeacherComment.do + +org.owasp.csrfguard.protected.previewDefineLater=/lams/tool/laprev11/authoring/definelater.do +org.owasp.csrfguard.protected.pixirDefineLater=/lams/tool/lapixl10/authoring/definelater.do + +org.owasp.csrfguard.protected.sbmtDefineLater=/lams/tool/lasbmt11/authoring/definelater.do org.owasp.csrfguard.protected.sbmtSubmissionDeadline=/lams/tool/lasbmt11/monitoring/setSubmissionDeadline.do + +org.owasp.csrfguard.protected.scribeDefineLater=/lams/tool/lascrb11/authoring/definelater.do + +org.owasp.csrfguard.protected.scratchieDefineLater=/lams/tool/lascrt11/authoring/definelater.do org.owasp.csrfguard.protected.scratchieSubmissionDeadline=/lams/tool/lascrt11/monitoring/setSubmissionDeadline.do -org.owasp.csrfguard.protected.shareresourcesChangeItemVisibility=/lams/tool/larsrc11/monitoring/changeItemVisibility.do + +org.owasp.csrfguard.protected.spreadsheetDefineLater=/lams/tool/lasprd10/authoring/definelater.do + +org.owasp.csrfguard.protected.surveyDefineLater=/lams/tool/lasurv11/authoring/definelater.do org.owasp.csrfguard.protected.surveySubmissionDeadline=/lams/tool/lasurv11/monitoring/setSubmissionDeadline.do + +org.owasp.csrfguard.protected.taskDefineLater=/lams/tool/latask10/authoring/definelater.do org.owasp.csrfguard.protected.taskSubmissionDeadline=/lams/tool/latask10/monitoring/setSubmissionDeadline.do org.owasp.csrfguard.protected.taskSetVerifyByMonitor=/lams/tool/latask10/monitoring/setVerifiedByMonitor.do + +org.owasp.csrfguard.protected.voteDefineLater=/lams/tool/lavote11/authoring/definelater.do org.owasp.csrfguard.protected.voteSubmissionDeadline=/lams/tool/lavote11/monitoring/setSubmissionDeadline.do + +org.owasp.csrfguard.protected.wikiDefineLater=/lams/tool/lawiki10/authoring/definelater.do org.owasp.csrfguard.protected.wikiSubmissionDeadline=/lams/tool/lawiki10/monitoring/setSubmissionDeadline.do +org.owasp.csrfguard.protected.zoomDefineLater=/lams/tool/lazoom10/authoring/definelater.do # Actions to take when a CSRF attack is attempted org.owasp.csrfguard.action.Log=org.owasp.csrfguard.action.Log Index: lams_tool_larsrc/web/WEB-INF/web.xml =================================================================== diff -u -rf013da27a40a5c84f59bdce2a1b1dec3fc938d28 -r71601beccc7097451a521af6ccf11139f5b6b0c5 --- lams_tool_larsrc/web/WEB-INF/web.xml (.../web.xml) (revision f013da27a40a5c84f59bdce2a1b1dec3fc938d28) +++ lams_tool_larsrc/web/WEB-INF/web.xml (.../web.xml) (revision 71601beccc7097451a521af6ccf11139f5b6b0c5) @@ -62,6 +62,10 @@ UTF-8 + + CSRFGuard + org.owasp.csrfguard.CsrfGuardFilter + hibernateFilter @@ -79,6 +83,10 @@ LocaleFilter /* + + CSRFGuard + *.do + @@ -167,14 +175,14 @@ tags-lams /WEB-INF/tlds/lams/lams.tld - - - - - - csrfguard - /WEB-INF/tlds/security/csrfguard.tld - + + + + + + csrfguard + /WEB-INF/tlds/security/csrfguard.tld + Index: lams_tool_larsrc/web/common/taglibs.jsp =================================================================== diff -u -rf013da27a40a5c84f59bdce2a1b1dec3fc938d28 -r71601beccc7097451a521af6ccf11139f5b6b0c5 --- lams_tool_larsrc/web/common/taglibs.jsp (.../taglibs.jsp) (revision f013da27a40a5c84f59bdce2a1b1dec3fc938d28) +++ lams_tool_larsrc/web/common/taglibs.jsp (.../taglibs.jsp) (revision 71601beccc7097451a521af6ccf11139f5b6b0c5) @@ -1,4 +1,5 @@ <%@ page language="java" errorPage="/error.jsp" pageEncoding="UTF-8" contentType="text/html;charset=utf-8" %> +<%@ taglib uri="csrfguard" prefix="csrf" %> <%@ taglib uri="tags-function" prefix="fn" %> <%@ taglib uri="tags-core" prefix="c" %> <%@ taglib uri="tags-fmt" prefix="fmt" %> Index: lams_tool_leader/web/WEB-INF/web.xml =================================================================== diff -u -r8a0116b9f105c1a090bd8adbac814e54f32673e3 -r71601beccc7097451a521af6ccf11139f5b6b0c5 --- lams_tool_leader/web/WEB-INF/web.xml (.../web.xml) (revision 8a0116b9f105c1a090bd8adbac814e54f32673e3) +++ lams_tool_leader/web/WEB-INF/web.xml (.../web.xml) (revision 71601beccc7097451a521af6ccf11139f5b6b0c5) @@ -44,6 +44,10 @@ org.lamsfoundation.lams.web.filter.LocaleFilter + + CSRFGuard + org.owasp.csrfguard.CsrfGuardFilter + SystemSessionFilter @@ -61,6 +65,10 @@ LocaleFilter /* + + CSRFGuard + *.do + @@ -156,14 +164,14 @@ tags-lams /WEB-INF/tlds/lams/lams.tld - - - - - - csrfguard - /WEB-INF/tlds/security/csrfguard.tld - + + + + + + csrfguard + /WEB-INF/tlds/security/csrfguard.tld + Index: lams_tool_leader/web/common/taglibs.jsp =================================================================== diff -u -r8a0116b9f105c1a090bd8adbac814e54f32673e3 -r71601beccc7097451a521af6ccf11139f5b6b0c5 --- lams_tool_leader/web/common/taglibs.jsp (.../taglibs.jsp) (revision 8a0116b9f105c1a090bd8adbac814e54f32673e3) +++ lams_tool_leader/web/common/taglibs.jsp (.../taglibs.jsp) (revision 71601beccc7097451a521af6ccf11139f5b6b0c5) @@ -1,5 +1,5 @@ <%@ page language="java" pageEncoding="UTF-8" contentType="text/html;charset=utf-8"%> - +<%@ taglib uri="csrfguard" prefix="csrf" %> <%@ taglib uri="tags-core" prefix="c"%> <%@ taglib uri="tags-fmt" prefix="fmt"%> <%@ taglib uri="tags-lams" prefix="lams"%>