1234567891011121314151617181920212223242526272829303132333435363738 |
- /*
- * Copyright 2002-2017 the original author or authors.
- *
- * Licensed under the Apache License, Version 2.0 (the "License");
- * you may not use this file except in compliance with the License.
- * You may obtain a copy of the License at
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
- * Unless required by applicable law or agreed to in writing, software
- * distributed under the License is distributed on an "AS IS" BASIS,
- * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- * See the License for the specific language governing permissions and
- * limitations under the License.
- */
- package sample;
- import org.springframework.security.web.server.csrf.CsrfToken;
- import org.springframework.web.bind.annotation.ControllerAdvice;
- import org.springframework.web.bind.annotation.ModelAttribute;
- import org.springframework.web.server.ServerWebExchange;
- import reactor.core.publisher.Mono;
- import static org.springframework.security.web.reactive.result.view.CsrfRequestDataValueProcessor.DEFAULT_CSRF_ATTR_NAME;
- /**
- * @author Rob Winch
- * @since 5.0
- */
- @ControllerAdvice
- public class CsrfControllerAdvice {
- @ModelAttribute
- public Mono<CsrfToken> csrfToken(ServerWebExchange exchange) {
- Mono<CsrfToken> csrfToken = exchange.getAttribute(CsrfToken.class.getName());
- return csrfToken.doOnSuccess(token -> exchange.getAttributes().put(DEFAULT_CSRF_ATTR_NAME, token));
- }
- }
|