Fix CsrfWebFilter error message when expected CSRF not found

Closes gh-9337
This commit is contained in:
Rob Winch
2021-01-12 11:18:29 -06:00
parent 160a4a3676
commit a1083d9a5c
2 changed files with 4 additions and 2 deletions

View File

@@ -132,7 +132,7 @@ public class CsrfWebFilter implements WebFilter {
private Mono<Void> validateToken(ServerWebExchange exchange) {
return this.csrfTokenRepository.loadToken(exchange)
.switchIfEmpty(Mono
.defer(() -> Mono.error(new CsrfException("CSRF Token has been associated to this client"))))
.defer(() -> Mono.error(new CsrfException("An expected CSRF token cannot be found"))))
.filterWhen((expected) -> containsValidCsrfToken(exchange, expected))
.switchIfEmpty(Mono.defer(() -> Mono.error(new CsrfException("Invalid CSRF Token")))).then();
}