[uportal-user] Disable csrf (for testing) in uP5

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[uportal-user] Disable csrf (for testing) in uP5

Benito J. Gonzalez-2
Hi folks,

Had a need to disable CSRF checks for testing purposes. For uportal 5, add the following bean in /overlays/uPortal/src/main/resources/properties/contextOverrides/overridesContext.xml:

```
 <!-- ignore csrf for now ... DO NOT DEPLOY TO PROD -->
<bean id="portalCsrfSecurityRequestMatcher"
class="org.springframework.security.web.util.matcher.NegatedRequestMatcher">
<constructor-arg>
<bean class="org.springframework.security.web.util.matcher.AnyRequestMatcher"/>
</constructor-arg>
</bean>
```

Remember to remove this to re-enable CSRF.

Hope someone finds this useful!
--bjagg

Benito J. Gonzalez
Software Developer
Unicon, Inc.
Voice:  480.558.2360
 Text:  209.777.2754
Email:  [hidden email]
GitHub:  bjagg
GitLab:  bjagg
BitBucket:  bjagg


--
You received this message because you are subscribed to the Google Groups "uPortal Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
Visit this group at https://groups.google.com/a/apereo.org/group/uportal-user/.