17
17
package org.springframework.security.config.web.server
18
18
19
19
import org.springframework.security.web.server.authorization.ServerAccessDeniedHandler
20
- import org.springframework.security.web.server.csrf.CsrfWebFilter
21
20
import org.springframework.security.web.server.csrf.ServerCsrfTokenRepository
22
21
import org.springframework.security.web.server.csrf.ServerCsrfTokenRequestHandler
23
22
import org.springframework.security.web.server.util.matcher.ServerWebExchangeMatcher
@@ -32,8 +31,6 @@ import org.springframework.security.web.server.util.matcher.ServerWebExchangeMat
32
31
* @property csrfTokenRepository the [ServerCsrfTokenRepository] used to persist the CSRF token.
33
32
* @property requireCsrfProtectionMatcher the [ServerWebExchangeMatcher] used to determine when CSRF protection
34
33
* is enabled.
35
- * @property tokenFromMultipartDataEnabled if true, the [CsrfWebFilter] should try to resolve the actual CSRF
36
- * token from the body of multipart data requests.
37
34
* @property csrfTokenRequestHandler the [ServerCsrfTokenRequestHandler] that is used to make the CSRF token
38
35
* available as an exchange attribute
39
36
*/
@@ -42,8 +39,6 @@ class ServerCsrfDsl {
42
39
var accessDeniedHandler: ServerAccessDeniedHandler ? = null
43
40
var csrfTokenRepository: ServerCsrfTokenRepository ? = null
44
41
var requireCsrfProtectionMatcher: ServerWebExchangeMatcher ? = null
45
- @Deprecated(" Use 'csrfTokenRequestHandler' instead" )
46
- var tokenFromMultipartDataEnabled: Boolean? = null
47
42
var csrfTokenRequestHandler: ServerCsrfTokenRequestHandler ? = null
48
43
49
44
private var disabled = false
@@ -60,7 +55,6 @@ class ServerCsrfDsl {
60
55
accessDeniedHandler?.also { csrf.accessDeniedHandler(accessDeniedHandler) }
61
56
csrfTokenRepository?.also { csrf.csrfTokenRepository(csrfTokenRepository) }
62
57
requireCsrfProtectionMatcher?.also { csrf.requireCsrfProtectionMatcher(requireCsrfProtectionMatcher) }
63
- tokenFromMultipartDataEnabled?.also { csrf.tokenFromMultipartDataEnabled(tokenFromMultipartDataEnabled!! ) }
64
58
csrfTokenRequestHandler?.also { csrf.csrfTokenRequestHandler(csrfTokenRequestHandler) }
65
59
if (disabled) {
66
60
csrf.disable()
0 commit comments