CSRF w/ load balancers

28 views
Skip to first unread message

Jamiel Sheikh

unread,
Oct 19, 2017, 1:44:32 AM10/19/17
to play-fr...@googlegroups.com
I have the Play CSRF filter enabled and my app is running on two server instances, with a load balancer in front. Given that a CSRF token is tied to a server, there is a 50% chance a form that I submit with the CSRF will fail. 

Does Play have a way to replicate CSRF tokens across Play instances? Or is there another approach to using CSRF tokens when stickiness to a server instance can't be guaranteed? Thanks kindly
Reply all
Reply to author
Forward
0 new messages