-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Closed
Labels
in: webAn issue in web modules (web, webmvc)An issue in web modules (web, webmvc)type: breaks-passivityA change that breaks passivity with the previous releaseA change that breaks passivity with the previous release
Milestone
Description
We should default to Xor CSRF tokens in 6.0:
- Use
XorCsrfTokenRequestAttributeHandler
inCsrfFilter
- Use
XorServerCsrfTokenRequestAttributeHandler
inCsrfWebFilter
Related gh-4001
Metadata
Metadata
Assignees
Labels
in: webAn issue in web modules (web, webmvc)An issue in web modules (web, webmvc)type: breaks-passivityA change that breaks passivity with the previous releaseA change that breaks passivity with the previous release