Skip to content

Default to Xor CSRF protection #11960

Closed
Closed
@sjohnr

Description

@sjohnr

We should default to Xor CSRF tokens in 6.0:

  • Use XorCsrfTokenRequestAttributeHandler in CsrfFilter
  • Use XorServerCsrfTokenRequestAttributeHandler in CsrfWebFilter

Related gh-4001

Metadata

Metadata

Assignees

Labels

in: webAn issue in web modules (web, webmvc)type: breaks-passivityA change that breaks passivity with the previous release

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions