From 564d80212a2030c9532cc836d11ecbd4dfcd0440 Mon Sep 17 00:00:00 2001 From: MathewFrancis Date: Thu, 15 May 2025 14:31:42 +0530 Subject: [PATCH] XSRF added but not implemented --- .../example/cezenPBX/config/CezenLoginSecurityChain.java | 7 +++++++ .../com/example/cezenPBX/controller/SignUpController.java | 2 +- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/config/CezenLoginSecurityChain.java b/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/config/CezenLoginSecurityChain.java index 191651c..6e2d1a6 100644 --- a/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/config/CezenLoginSecurityChain.java +++ b/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/config/CezenLoginSecurityChain.java @@ -64,7 +64,14 @@ public class CezenLoginSecurityChain { })) + //temporarily disabling cross sight resource forgery .csrf(AbstractHttpConfigurer::disable) +// .csrf((csrf) -> +// csrf.csrfTokenRequestHandler(requestHandler). +// ignoringRequestMatchers("/open/signup","/open/login","/user/getXSRfToken") +// //.csrfTokenRepository(new CookieCsrfTokenRepository()) +// .csrfTokenRepository(cookieCsrfTokenRepo) +// ) //.addFilterAfter(new CsrfCookieFilter(), BasicAuthenticationFilter.class) //token generation after BasicAuthenticationFilter.class diff --git a/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/controller/SignUpController.java b/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/controller/SignUpController.java index d78b506..d982a11 100644 --- a/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/controller/SignUpController.java +++ b/MySQL_conf_pbx/test1/springCezenPBX/src/main/java/com/example/cezenPBX/controller/SignUpController.java @@ -29,7 +29,7 @@ public class SignUpController { // and a login route @GetMapping("/login") public ReturnStatus login(){ - return new ReturnStatus(false, "Login not yet implemented", "Login not yet implemented"); + return new ReturnStatus(true, "Welcome user authenticated successfully", ""); }