Spring Security 3.2 CSRF disable for specific URLs

后端 未结 7 1936
梦毁少年i
梦毁少年i 2020-12-08 02:32

Enabled CSRF in my Spring MVC application using Spring security 3.2.

My spring-security.xml


 

        
7条回答
  •  温柔的废话
    2020-12-08 03:13

    
        
    
        
            
        
    
        ...
    
    
    
        
        
            
              
                
              
            
        
    
    

    mean of

     http
            .csrf()
                // ignore our stomp endpoints since they are protected using Stomp headers
                .ignoringAntMatchers("/chat/**")
    

    example from : https://docs.spring.io/spring-security/site/docs/4.1.x/reference/htmlsingle/

提交回复
热议问题