exploits.adoc 670 B

1234567891011
  1. = Exploit Protection Migrations
  2. The following steps relate to how to finish migrating exploit protection support.
  3. == CSRF BREACH with WebSocket support
  4. In Spring Security 5.8, the default `ChannelInterceptor` for making the `CsrfToken` available with xref:servlet/integrations/websocket.adoc[WebSocket Security] is `CsrfChannelInterceptor`.
  5. `XorCsrfChannelInterceptor` was added to allow opting into CSRF BREACH support.
  6. In Spring Security 6, `XorCsrfChannelInterceptor` is the default `ChannelInterceptor` for making the `CsrfToken` available.
  7. If you configured the `XorCsrfChannelInterceptor` only for the purpose of updating to 6.0, you can remove it completely.