CsrfAuthenticationStrategy is not consistent with CsrfFilter #12235
Labels
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: bug
A general bug
Milestone
We should default to Xor CSRF tokens in 6.0, but
CsrfAuthenticationStrategy
still usesCsrfTokenRequestAttributeHandler
by default instead ofXorCsrfTokenRequestAttributeHandler
.Related gh-11960
The text was updated successfully, but these errors were encountered: