From ed3bd892d77e5b79720cb72d2f4bd53c4d603c0c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sebasti=C3=A1n=20L=C3=B3pez=20O?= Date: Sun, 6 Jul 2025 20:55:34 -0500 Subject: [PATCH] Potential fix for code scanning alert no. 6: Disabled Spring CSRF protection Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .../smartpot/com/api/Security/Config/SecurityConfiguration.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/main/java/smartpot/com/api/Security/Config/SecurityConfiguration.java b/src/main/java/smartpot/com/api/Security/Config/SecurityConfiguration.java index c70722e..2396cfc 100644 --- a/src/main/java/smartpot/com/api/Security/Config/SecurityConfiguration.java +++ b/src/main/java/smartpot/com/api/Security/Config/SecurityConfiguration.java @@ -59,7 +59,7 @@ public SecurityFilterChain securityFilterChain(HttpSecurity httpSec) throws Exce } return httpSec - .csrf(AbstractHttpConfigurer::disable) // Enable CSRF protection + .csrf(Customizer.withDefaults()) // Enable CSRF protection .cors(cors -> cors.configurationSource(corsConfig)) .authorizeHttpRequests(authorizationManagerRequestMatcherRegistry -> { authorizationManagerRequestMatcherRegistry.requestMatchers(publicRoutesList.toArray(new String[0])).permitAll();