1
0
Files
spring-security-demo/cors-csrf/src/main/resources/application.yml
2026-08-28 10:16:21 +05:30

26 lines
881 B
YAML

# Every scenario in the article is a profile. The default is `securitysource`, the
# configuration that works, so that a bare `mvn spring-boot:run` starts something sane.
spring:
application:
name: cors-csrf-samesite
profiles:
default: securitysource
server:
port: 8080
servlet:
session:
cookie:
# Boot writes exactly what you put here. It does NOT add `Secure` for you when
# same-site is `none`, which is the whole subject of docs/07-samesite.md. Flip
# SESSION_SAME_SITE / SESSION_SECURE from scripts/scenario-samesite.sh and read the
# emitted Set-Cookie header back.
same-site: ${SESSION_SAME_SITE:lax}
secure: ${SESSION_SECURE:false}
http-only: true
logging:
level:
org.springframework.security.web.csrf: ${CSRF_LOG_LEVEL:INFO}
org.springframework.web.cors: ${CORS_LOG_LEVEL:INFO}