Default to Xor CSRF protection #11960
Labels
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
Milestone
We should default to Xor CSRF tokens in 6.0:
XorCsrfTokenRequestAttributeHandler
inCsrfFilter
XorServerCsrfTokenRequestAttributeHandler
inCsrfWebFilter
Related gh-4001
The text was updated successfully, but these errors were encountered: