Преглед на файлове

Correct Explanation for HttpSessionCsrfTokenRepository

Junhyunny преди 1 година
родител
ревизия
bfee6927c2
променени са 1 файла, в които са добавени 1 реда и са изтрити 1 реда
  1. 1 1
      docs/modules/ROOT/pages/servlet/exploits/csrf.adoc

+ 1 - 1
docs/modules/ROOT/pages/servlet/exploits/csrf.adoc

@@ -130,7 +130,7 @@ You can also specify <<csrf-token-repository-custom,your own implementation>> to
 
 By default, Spring Security stores the expected CSRF token in the `HttpSession` by using {security-api-url}org/springframework/security/web/csrf/HttpSessionCsrfTokenRepository.html[`HttpSessionCsrfTokenRepository`], so no additional code is necessary.
 
-The `HttpSessionCsrfTokenRepository` reads the token from an HTTP request header named `X-CSRF-TOKEN` or the request parameter `_csrf` by default.
+The `HttpSessionCsrfTokenRepository` reads the token from a session (whether in-memory, cache, or database). If you need to access the session attribute directly, please first configure the session attribute name using HttpSessionCsrfTokenRepository#setSessionAttributeName.
 
 You can specify the default configuration explicitly using the following configuration: