You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 519bd29
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: example/README.md
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -142,7 +142,9 @@ The main configuration file `src/main/resources/application.yaml` is shared by a
142
142
143
143
Besides configuration settings, the trusted certificate authority certificates may need to be configured as described in section [_3. Configure the trusted certificate authority certificates_](#3-configure-the-trusted-certificate-authority-certificates) above.
144
144
145
-
Spring Security has CSRF protection enabled by default. Web eID requires CSRF protection.
145
+
Spring Security has CSRF protection enabled by default. Web eID requires CSRF protection. By default, the frontend reads
146
+
CSRF tokens from Thymeleaf meta tags. Set `web-eid-auth-token.csrf.use-spa-configuration=true` to use Spring Security's
147
+
SPA-compatible CSRF setup with a JavaScript-readable `XSRF-TOKEN` cookie.
0 commit comments