CsrfControllerAdvice.java 1.4 KB

1234567891011121314151617181920212223242526272829303132333435363738
  1. /*
  2. * Copyright 2002-2017 the original author or authors.
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * http://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. package sample;
  17. import org.springframework.security.web.server.csrf.CsrfToken;
  18. import org.springframework.web.bind.annotation.ControllerAdvice;
  19. import org.springframework.web.bind.annotation.ModelAttribute;
  20. import org.springframework.web.server.ServerWebExchange;
  21. import reactor.core.publisher.Mono;
  22. import static org.springframework.security.web.reactive.result.view.CsrfRequestDataValueProcessor.DEFAULT_CSRF_ATTR_NAME;
  23. /**
  24. * @author Rob Winch
  25. * @since 5.0
  26. */
  27. @ControllerAdvice
  28. public class CsrfControllerAdvice {
  29. @ModelAttribute
  30. public Mono<CsrfToken> csrfToken(ServerWebExchange exchange) {
  31. Mono<CsrfToken> csrfToken = exchange.getAttribute(CsrfToken.class.getName());
  32. return csrfToken.doOnSuccess(token -> exchange.getAttributes().put(DEFAULT_CSRF_ATTR_NAME, token));
  33. }
  34. }