Skip to content

fix: do not allow simple requests for login#4823

Open
achmelo wants to merge 11 commits into
v3.x.xfrom
reboot/login-csrf
Open

fix: do not allow simple requests for login#4823
achmelo wants to merge 11 commits into
v3.x.xfrom
reboot/login-csrf

Conversation

@achmelo

@achmelo achmelo commented Jul 17, 2026

Copy link
Copy Markdown
Member

Description

Require content-type=application/json for login request. Respond with 415 in case of other content types.

Linked to # (issue)
Part of the # (epic)

Type of change

  • fix: Bug fix (non-breaking change which fixes an issue)
  • feat: New feature (non-breaking change which adds functionality)
  • docs: Change in a documentation
  • refactor: Refactor the code
  • chore: Chore, repository cleanup, updates the dependencies.
  • BREAKING CHANGE or !: Breaking change (fix or feature that would cause existing functionality to not work as expected)

Checklist:

  • My code follows the style guidelines of this project
  • PR title conforms to commit message guideline ## Commit Message Structure Guideline
  • I have commented my code, particularly in hard-to-understand areas. In JS I did provide JSDoc
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • The java tests in the area I was working on leverage @nested annotations
  • Any dependent changes have been merged and published in downstream modules

For more details about how should the code look like read the Contributing guideline

achmelo added 3 commits July 16, 2026 11:17
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
@github-actions github-actions Bot added the Sensitive Sensitive change that requires peer review label Jul 17, 2026
@pablocarle

Copy link
Copy Markdown
Contributor

This may qualify as a breaking change as well. I remember having to do some custom logic in the login controller to keep the behaviour the same as before.

achmelo and others added 4 commits July 17, 2026 11:23
…_ATTR. Using defaultIfEmpty (rather than switchIfEmpty) guarantees the chain is filtered exactly once. chain.filter(...) returns Mono<Void>, which completes without emitting a value, so a switchIfEmpty placed after it would always fire its fallback and invoke the downstream chain (and the controller) a second time.

Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
achmelo added 3 commits July 20, 2026 15:54
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Sensitive Sensitive change that requires peer review size/XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants