Skip to content

Conversation

sjohnr
Copy link
Contributor

@sjohnr sjohnr commented Jan 18, 2023

No description provided.

@sjohnr sjohnr force-pushed the gh-12378-csrf-websocket-stomp branch from 51677bc to 4093468 Compare January 19, 2023 16:41
@sjohnr sjohnr marked this pull request as ready for review January 19, 2023 16:44
@sjohnr sjohnr linked an issue Jan 19, 2023 that may be closed by this pull request
@sjohnr sjohnr self-assigned this Jan 19, 2023
@sjohnr sjohnr requested a review from rwinch January 19, 2023 16:45
@sjohnr sjohnr added status: duplicate A duplicate of another issue in: messaging An issue in spring-security-messaging type: bug A general bug labels Jan 19, 2023
@sjohnr sjohnr force-pushed the gh-12378-csrf-websocket-stomp branch 3 times, most recently from 98e6a69 to 3bcddd4 Compare January 19, 2023 21:58
Copy link
Member

@rwinch rwinch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @sjohnr Overall this looks good. Once you have resolved the comments, from my perspective you can merge this.

@sjohnr sjohnr force-pushed the gh-12378-csrf-websocket-stomp branch from 3bcddd4 to dbe56d5 Compare January 23, 2023 21:40
@sjohnr sjohnr added this to the 5.8.2 milestone Jan 23, 2023
@sjohnr sjohnr removed the status: duplicate A duplicate of another issue label Jan 23, 2023
@sjohnr
Copy link
Contributor Author

sjohnr commented Jan 23, 2023

Note: Once this PR is merged, we can close gh-12378 by making XorCsrfChannelInterceptor the default in WebSocketMessageBrokerSecurityConfiguration.csrfChannelInterceptor.

@sjohnr sjohnr force-pushed the gh-12378-csrf-websocket-stomp branch from dbe56d5 to 33e72b3 Compare January 26, 2023 04:27
@sjohnr sjohnr merged commit 33e72b3 into spring-projects:5.8.x Jan 26, 2023
@sjohnr sjohnr deleted the gh-12378-csrf-websocket-stomp branch January 26, 2023 21:50
@sjohnr sjohnr added type: enhancement A general enhancement and removed type: bug A general bug labels Jan 26, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in: messaging An issue in spring-security-messaging type: enhancement A general enhancement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants