Package org.springframework.security.web.server.csrf
package org.springframework.security.web.server.csrf
-
ClassDescriptionA
ServerCsrfTokenRepository
that persists the CSRF token in a cookie named "XSRF-TOKEN" and reads from the header "X-XSRF-TOKEN" following the conventions of AngularJS.Thrown when an invalid or missingCsrfToken
is found in the HttpServletRequestCsrfServerLogoutHandler
is in charge of removing theCsrfToken
upon logout.Applies CSRF protection using a synchronizer token pattern.A CSRF token that is used to protect against CSRF attacks.An API to allow changing the method in which the expectedCsrfToken
is associated to theServerWebExchange
.