Skip to content

SEC-2356: Default for invalid CSRF Token with no user should logout #2583

@spring-projects-issues

Description

@spring-projects-issues

Rob Winch (Migrated from SEC-2356) said:

This will drastically improve the usability for a user who has an expired session in circumstances other than log in.

Metadata

Metadata

Assignees

No one assigned

    Labels

    in: configAn issue in spring-security-configtype: enhancementA general enhancementtype: jiraAn issue that was migrated from JIRA

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions