[5.5] add fullUrl wildcards to except array in VerifyCsrfToken #22661
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This is an improvement on the following PR that is already merged into 5.5.
#22619
The former PR made sure full URLs could be passed in the
except
array of the VerifyCsrfToken middleware. This PR adds wildcard support for full URLs as well. It is fully compatible with existing behaviour: both paths and full URLs can be added, with or without the*
wildcard. e.g.This PR contains tests on both the matching logic as well as for the request::fullUrlIs() method, which is used in the VerifyCsrfToken middleware.