@AutoConfiguration @ConditionalOnWebApplication(type = ConditionalOnWebApplication.Type.SERVLET) @ConditionalOnBooleanProperty(name = "grails.security.headers.enabled", matchIfMissing = true) @EnableConfigurationProperties(GrailsSecurityHeadersProperties.class) public class GrailsSecurityHeadersAutoConfiguration extends java.lang.Object
Registers GrailsSecurityHeadersFilter to apply baseline browser-hardening response headers. The filter writes at response commit time and only fills headers that are still absent, so it coexists with Spring Security's header writers and any other filter or controller that sets these headers itself.
The filter is registered at GrailsFilters.FIRST, the outermost Grails slot. Commit-time writers nest, and the innermost fires first, so the outermost one is the last to write and therefore the one that only fills gaps; that is what lets every filter inside it (Spring Security at Spring Boot's default filter order, SiteMesh, an application filter) win. Being outermost among the Grails filters also means a filter that serves the response itself without continuing the chain, as the asset-pipeline filter does for static assets, still passes through this filter's response wrapper and receives the headers.
Filters ordered ahead of GrailsFilters.FIRST run outside this one. Spring
Boot's forwarded-header filter and, in a WAR deployment, its error-page filter are such
filters, as is a Spring Security chain whose spring.security.filter.order is set
below GrailsFilters.FIRST. In that arrangement Spring Security's writers run after the
Grails defaults have been written, and those of them that only fill absent headers
(every writer but XFrameOptionsHeaderWriter) leave the Grails value in place;
disable the corresponding grails.security.headers.<header> to let such a writer
own the header.
Both beans back off when the application declares its own
GrailsSecurityHeadersFilter bean, a bean named grailsSecurityHeadersFilter,
or a FilterRegistrationBean whose declared filter type is
GrailsSecurityHeadersFilter.
| Type Params | Return Type | Name and description |
|---|---|---|
|
public FilterRegistrationBean<GrailsSecurityHeadersFilter> |
grailsSecurityHeadersFilter(GrailsSecurityHeadersFilter securityHeadersFilter) |
|
public GrailsSecurityHeadersFilter |
securityHeadersFilter(GrailsSecurityHeadersProperties properties, Environment environment) |
| Methods inherited from class | Name |
|---|---|
class java.lang.Object |
java.lang.Object#equals(java.lang.Object), java.lang.Object#getClass(), java.lang.Object#hashCode(), java.lang.Object#notify(), java.lang.Object#notifyAll(), java.lang.Object#toString(), java.lang.Object#wait(), java.lang.Object#wait(long), java.lang.Object#wait(long, int) |