From 684923cac5e35bb02f4b45c6deaa2ef7d20dcba2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Jerna=C5=9B?= Date: Fri, 25 Sep 2026 15:16:55 +0200 Subject: [PATCH] Replace some OWASP links with current versions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Łukasz Jernaś --- .idea/checkstyle-idea.xml | 21 +++++++++---------- .../web/configurers/CsrfConfigurer.java | 2 +- .../config/web/server/ServerHttpSecurity.java | 4 ++-- .../ROOT/pages/features/exploits/headers.adoc | 2 +- .../security/web/csrf/CsrfFilter.java | 2 +- .../web/server/csrf/CsrfWebFilter.java | 2 +- 6 files changed, 16 insertions(+), 17 deletions(-) diff --git a/.idea/checkstyle-idea.xml b/.idea/checkstyle-idea.xml index bf41a5a9de3..81af434abfa 100644 --- a/.idea/checkstyle-idea.xml +++ b/.idea/checkstyle-idea.xml @@ -1,16 +1,15 @@ - - \ No newline at end of file diff --git a/config/src/main/java/org/springframework/security/config/annotation/web/configurers/CsrfConfigurer.java b/config/src/main/java/org/springframework/security/config/annotation/web/configurers/CsrfConfigurer.java index 3f67e91280e..ddd3d706db5 100644 --- a/config/src/main/java/org/springframework/security/config/annotation/web/configurers/CsrfConfigurer.java +++ b/config/src/main/java/org/springframework/security/config/annotation/web/configurers/CsrfConfigurer.java @@ -59,7 +59,7 @@ /** * Adds - * CSRF + * CSRF * protection for the methods as specified by * {@link #requireCsrfProtectionMatcher(RequestMatcher)}. * diff --git a/config/src/main/java/org/springframework/security/config/web/server/ServerHttpSecurity.java b/config/src/main/java/org/springframework/security/config/web/server/ServerHttpSecurity.java index a50d86e0035..5ba12168365 100644 --- a/config/src/main/java/org/springframework/security/config/web/server/ServerHttpSecurity.java +++ b/config/src/main/java/org/springframework/security/config/web/server/ServerHttpSecurity.java @@ -480,7 +480,7 @@ public ServerHttpSecurity redirectToHttps(Customizer httpsRed /** * Configures CSRF + * "https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html">CSRF * Protection which is enabled by default. You can disable it using: * *
@@ -1827,7 +1827,7 @@ protected void configure(ServerHttpSecurity http) {
 
 	/**
 	 * Configures CSRF
+	 * "https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html">CSRF
 	 * Protection.
 	 *
 	 * @author Rob Winch
diff --git a/docs/modules/ROOT/pages/features/exploits/headers.adoc b/docs/modules/ROOT/pages/features/exploits/headers.adoc
index f34419ab4fc..1fbaae12a86 100644
--- a/docs/modules/ROOT/pages/features/exploits/headers.adoc
+++ b/docs/modules/ROOT/pages/features/exploits/headers.adoc
@@ -179,7 +179,7 @@ Another modern approach to dealing with clickjacking is to use <>.
 ====
 
 There are a number ways to mitigate clickjacking attacks.
-For example, to protect legacy browsers from clickjacking attacks, you can use https://www.owasp.org/index.php/Clickjacking_Defense_Cheat_Sheet#Best-for-now_Legacy_Browser_Frame_Breaking_Script[frame breaking code].
+For example, to protect legacy browsers from clickjacking attacks, you can use https://cheatsheetseries.owasp.org/cheatsheets/Clickjacking_Defense_Cheat_Sheet.html#best-for-now-legacy-browser-frame-breaking-script[frame breaking code].
 While not perfect, the frame breaking code is the best you can do for the legacy browsers.
 
 A more modern approach to address clickjacking is to use https://developer.mozilla.org/en-US/docs/HTTP/X-Frame-Options[X-Frame-Options] header.
diff --git a/web/src/main/java/org/springframework/security/web/csrf/CsrfFilter.java b/web/src/main/java/org/springframework/security/web/csrf/CsrfFilter.java
index 20912ab8c07..e4b57f3a78d 100644
--- a/web/src/main/java/org/springframework/security/web/csrf/CsrfFilter.java
+++ b/web/src/main/java/org/springframework/security/web/csrf/CsrfFilter.java
@@ -43,7 +43,7 @@
 /**
  * 

* Applies - * CSRF + * CSRF * protection using a synchronizer token pattern. Developers are required to ensure that * {@link CsrfFilter} is invoked for any request that allows state to change. Typically * this just means that they should ensure their web application follows proper REST diff --git a/web/src/main/java/org/springframework/security/web/server/csrf/CsrfWebFilter.java b/web/src/main/java/org/springframework/security/web/server/csrf/CsrfWebFilter.java index 2c8a97f56b4..b6719839b9b 100644 --- a/web/src/main/java/org/springframework/security/web/server/csrf/CsrfWebFilter.java +++ b/web/src/main/java/org/springframework/security/web/server/csrf/CsrfWebFilter.java @@ -38,7 +38,7 @@ /** *

* Applies - * CSRF + * CSRF * protection using a synchronizer token pattern. Developers are required to ensure that * {@link CsrfWebFilter} is invoked for any request that allows state to change. Typically * this just means that they should ensure their web application follows proper REST