2021-10-30 00:09:04 +08:00
|
|
|
= Testing with CSRF
|
|
|
|
|
2021-12-14 06:57:36 +08:00
|
|
|
Spring Security also provides support for CSRF testing with `WebTestClient` -- for example:
|
2021-10-30 00:09:04 +08:00
|
|
|
|
|
|
|
====
|
|
|
|
.Java
|
|
|
|
[source,java,role="primary"]
|
|
|
|
----
|
|
|
|
this.rest
|
|
|
|
// provide a valid CSRF token
|
|
|
|
.mutateWith(csrf())
|
|
|
|
.post()
|
|
|
|
.uri("/login")
|
|
|
|
...
|
|
|
|
----
|
|
|
|
|
|
|
|
.Kotlin
|
|
|
|
[source,kotlin,role="secondary"]
|
|
|
|
----
|
|
|
|
this.rest
|
|
|
|
// provide a valid CSRF token
|
|
|
|
.mutateWith(csrf())
|
|
|
|
.post()
|
|
|
|
.uri("/login")
|
|
|
|
...
|
|
|
|
----
|
|
|
|
====
|