XSRF added but not implemented

This commit is contained in:
MathewFrancis 2025-05-15 14:31:42 +05:30
parent b328bc30a8
commit 564d80212a
2 changed files with 8 additions and 1 deletions

View File

@ -64,7 +64,14 @@ public class CezenLoginSecurityChain {
}))
//temporarily disabling cross sight resource forgery
.csrf(AbstractHttpConfigurer::disable)
// .csrf((csrf) ->
// csrf.csrfTokenRequestHandler(requestHandler).
// ignoringRequestMatchers("/open/signup","/open/login","/user/getXSRfToken")
// //.csrfTokenRepository(new CookieCsrfTokenRepository())
// .csrfTokenRepository(cookieCsrfTokenRepo)
// )
//.addFilterAfter(new CsrfCookieFilter(), BasicAuthenticationFilter.class)
//token generation after BasicAuthenticationFilter.class

View File

@ -29,7 +29,7 @@ public class SignUpController {
// and a login route
@GetMapping("/login")
public ReturnStatus login(){
return new ReturnStatus(false, "Login not yet implemented", "Login not yet implemented");
return new ReturnStatus(true, "Welcome user authenticated successfully", "");
}