Jerry's Fiori CRSF token collection

130 阅读1分钟

How is note creation implemented - csrf token logic

Created by Wang, Jerry, last modified on Jan 16, 2015

clipboard1
clipboard2
clipboard3
clipboard4
clipboard5
clipboard6

Handling in the backend

Created by Wang, Jerry, last modified on Mar 06, 2015

clipboard7
clipboard8
clipboard9
clipboard10
clipboard11
clipboard12
clipboard13
clipboard14
clipboard15
clipboard16

csrf check switch

Created by Wang, Jerry, last modified on Mar 12, 2015

clipboard17
clipboard18
clipboard19
clipboard20
clipboard21

CSRF token validation failed

Created by Wang, Jerry, last modified on Mar 24, 2015

clipboard22
clipboard23
clipboard24
clipboard25

CL_HTTP_SECURITY_SESSION_ICF security_context how csrf token is generated in fallback scenario

Created by Wang, Jerry, last modified on Jun 16, 2016

clipboard26

clipboard27

clipboard28

clipboard29

clipboard30

clipboard31

clipboard32

clipboard33

clipboard34

clipboard35

clipboard36

clipboard37

clipboard38

clipboard39

clipboard40

frontend

CSRF token handling in Framework

Created by Wang, Jerry, last modified on Mar 02, 2016

clipboard41

clipboard42

clipboard43

clipboard44

clipboard45

clipboard46

clipboard47

clipboard48

clipboard49

clipboard50

clipboard51

clipboard52

clipboard53

clipboard54

clipboard55

clipboard56

clipboard57

How to get a new CSRF token

Created by Wang, Jerry on Apr 23, 2015

create a new http request with following three http headers:
clipboard58

url: p271140.wdf.sap.corp:8301/sap/opu/oda…

Click send button, and you see http status code 200.

The new CSRF token is stored in field x-csrf-token.
clipboard59