Skip to content

Commit 8418aa8

Browse files
author
Gabriel Gutierrez
committed
Deleted apostrophes/quotation marks from CSRF token header value. This may cause issues with Spring CSRF filter validation
1 parent 650ca27 commit 8418aa8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

springdoc-openapi-common/src/main/java/org/springdoc/ui/AbstractSwaggerIndexTransformer.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -260,7 +260,7 @@ protected String addCSRFSessionStorage(String html) {
260260
stringBuilder.append("\t\t\tif (isSameOrigin) ");
261261
stringBuilder.append("request.headers['");
262262
stringBuilder.append(swaggerUiConfig.getCsrf().getHeaderName());
263-
stringBuilder.append("'] = value;\n");
263+
stringBuilder.append("'] = value.replace(/['\"]+/g,'');\n");
264264
stringBuilder.append("\t\t\treturn request;\n");
265265
stringBuilder.append("\t\t},\n");
266266
stringBuilder.append("\t\t" + PRESETS);

0 commit comments

Comments
 (0)