Man up and deal with CSRF in integration test
Fixes gh-979
This commit is contained in:
@@ -73,10 +73,6 @@ public class SampleWebSecureApplication extends WebMvcConfigurerAdapter {
|
||||
|
||||
@Override
|
||||
protected void configure(HttpSecurity http) throws Exception {
|
||||
if (!security.isEnableCsrf()) {
|
||||
// For testing
|
||||
http.csrf().disable();
|
||||
}
|
||||
http.authorizeRequests().anyRequest().fullyAuthenticated().and().formLogin()
|
||||
.loginPage("/login").failureUrl("/login?error").permitAll();
|
||||
}
|
||||
|
||||
@@ -27,7 +27,7 @@
|
||||
</fieldset>
|
||||
<input type="submit" id="login" value="Login"
|
||||
class="btn btn-primary" /> <input type="hidden"
|
||||
th:name="${_csrf.parameterName}" th:value="${_csrf.token}" th:if="${_csrf}"/>
|
||||
th:name="${_csrf.parameterName}" th:value="${_csrf.token}"/>
|
||||
</form>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user