代码之家  ›  专栏  ›  技术社区  ›  gerdemb

在谷歌应用引擎上运行的GWT应用程序是否受CSRF保护?

  •  3
  • gerdemb  · 技术社区  · 16 年前

    我正在开发一个在谷歌应用引擎上运行的GWT应用程序,我想知道我是否需要担心跨站点请求伪造,或者这会自动帮我解决?

    对于每个需要身份验证的RPC请求,我都有以下代码:

    public class BookServiceImpl extends RemoteServiceServlet implements
    BookService {
        public void deleteInventory(Key<Inventory> inventoryKey) throws NotLoggedInException,  InvalidStateException, NotFoundException {
            DAO dao = new DAO();
                // This will throw NotLoggedInException if user is not logged in
            User user = dao.getCurrentUser();
                // Do deletion here
        }
    }
    
    public final class DAO extends DAOBase {
        public User getCurrentUser() throws NotLoggedInException {
                currentUser = UserServiceFactory.getUserService().getCurrentUser();
                if(currentUser == null) {
                    throw new NotLoggedInException();
                }
            return currentUser;
        }
    

    我找不到任何关于 UserService 检查身份验证。是否足够依赖上面的代码,或者是否需要更多?我是这方面的初学者,但据我了解,要避免CSRF攻击,有些策略是:

    1. 在中添加身份验证令牌 请求有效负载而不是 检查cookie
    2. 正在检查HTTP 引用头

    我可以看到,我从谷歌上设置了Cookie和看起来像SID值的cookies,但是如果令牌被传递,我不能从有效载荷中的序列化Java对象中看出。我也不知道引用头是否被使用。

    那么,我担心的是一个非问题吗?如果不是,这里最好的策略是什么?这是一个很常见的问题,必须有标准的解决方案。

    1 回复  |  直到 16 年前
        1
  •  6
  •   Community Mohan Dere    9 年前

    如果您将相同的代码放入常规servlet中,那么您肯定容易受到XSRF的攻击。但既然你在使用GWT RemoteServiceServlet -答案取决于您使用的GWT版本。

    从尚未发布的GWT2.1开始,RPC机制添加请求头并验证这些头在RemoteServiceServlet中的存在。 This has its limitations -特别是,较旧版本的flash允许您从不同的域发送请求头,但它确实使潜在的攻击者更加困难。

    如果您想充分保护自己不受XSRF的影响,请参阅 Lombardi's Development blog . 博客讨论了两种技巧。第一个简单的改变是端口2.1改变了旧版本的GWT。第二种方法需要将会话标识符作为请求参数进行复制,这是防止XSRF的推荐方法。

    工具书类

    1. GWT RPC - Does it do enough to protect against CSRF?
    2. Lombardi development blog on GWT RPC and XSRF
    3. Security for GWT Applications