Class HstsFilter

java.lang.Object
alpine.server.filters.HstsFilter
All Implemented Interfaces:
javax.servlet.Filter

public class HstsFilter extends Object implements javax.servlet.Filter

Implements HTTP Strict Transport Security (HSTS) (RFC 6797).

This filter is configured via the applications web.xml.

     <init-param>
         <param-name>httpsPort</param-name>
         <param-value>443</param-value>
     </init-param>
     <init-param>
         <param-name>maxAge</param-name>
         <param-value>31536000</param-value>
     </init-param>
     <init-param>
         <param-name>includeSubdomains</param-name>
         <param-value>false</param-value>
     </init-param>
 
An example implementation in web.xml:
 <filter>
     <filter-name>HstsFilter</filter-name>
     <filter-class>alpine.filters.HstsFilter</filter-class>
     <init-param>
         <param-name>httpsPort</param-name>
         <param-value>443</param-value>
     </init-param>
     <init-param>
         <param-name>maxAge</param-name>
         <param-value>31536000</param-value>
     </init-param>
     <init-param>
         <param-name>includeSubdomains</param-name>
         <param-value>true</param-value>
     </init-param>
 </filter>
 <filter-mapping>
     <filter-name>HstsFilter</filter-name>
     <url-pattern>/*</url-pattern>
 </filter-mapping>
 
Since:
1.0.0
Author:
Steve Springett
  • Constructor Details

    • HstsFilter

      public HstsFilter()
  • Method Details

    • init

      public void init(javax.servlet.FilterConfig filterConfig) throws javax.servlet.ServletException
      Specified by:
      init in interface javax.servlet.Filter
      Throws:
      javax.servlet.ServletException
    • doFilter

      public void doFilter(javax.servlet.ServletRequest req, javax.servlet.ServletResponse resp, javax.servlet.FilterChain chain) throws javax.servlet.ServletException, IOException
      Specified by:
      doFilter in interface javax.servlet.Filter
      Throws:
      javax.servlet.ServletException
      IOException
    • destroy

      public void destroy()
      Specified by:
      destroy in interface javax.servlet.Filter