// Copyright (c) .NET Foundation. All rights reserved. // Licensed under the Apache License, Version 2.0. See License.txt in the project root for license information. using Microsoft.AspNetCore.Http; namespace Microsoft.AspNetCore.Antiforgery { /// /// Allows providing or validating additional custom data for antiforgery tokens. /// For example, the developer could use this to supply a nonce when the token is /// generated, then he could validate the nonce when the token is validated. /// /// /// The antiforgery system already embeds the client's username within the /// generated tokens. This interface provides and consumes supplemental /// data. If an incoming antiforgery token contains supplemental data but no /// additional data provider is configured, the supplemental data will not be /// validated. /// public interface IAntiforgeryAdditionalDataProvider { /// /// Provides additional data to be stored for the antiforgery tokens generated /// during this request. /// /// Information about the current request. /// Supplemental data to embed within the antiforgery token. string GetAdditionalData(HttpContext context); /// /// Validates additional data that was embedded inside an incoming antiforgery /// token. /// /// Information about the current request. /// Supplemental data that was embedded within the token. /// True if the data is valid; false if the data is invalid. bool ValidateAdditionalData(HttpContext context, string additionalData); } }