Browse Source

Merge pull request #7253 from abpframework/auto-merge/rel-4-2/83

Merge branch dev with rel-4.2
pull/7262/head
Mehmet Erim 6 years ago
committed by GitHub
parent
commit
6cd45a3dcc
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
  1. 17
      docs/en/CSRF-Anti-Forgery.md
  2. 2
      framework/src/Volo.Abp.Cli.Core/Volo/Abp/Cli/ProjectBuilding/Templates/App/AppTemplateBase.cs

17
docs/en/CSRF-Anti-Forgery.md

@ -144,4 +144,19 @@ Let's talk about why.
First, take a look at [Angular's code](https://github.com/angular/angular/blob/master/packages/common/http/src/xsrf.ts#L81) First, take a look at [Angular's code](https://github.com/angular/angular/blob/master/packages/common/http/src/xsrf.ts#L81)
It does not intercept any request that starts with `http://` or `https://`. There is a good reason for that. Any cross-site request does not need this token for security. This verification is only valid if the request is made to the same domain from which the web page is served. So, simply put, if you serve everything from a single domain, you just use a relative path. It does not intercept any request that starts with `http://` or `https://`. There is a good reason for that. Any cross-site request does not need this token for security. This verification is only valid if the request is made to the same domain from which the web page is served. So, simply put, if you serve everything from a single domain, you just use a relative path.
If you serve your APIs from the root, i.e. no context root (https://testdomain.com/api/identity/users), leave `url` empty as follows:
```typescript
export const environment = {
production: true,
// ....
apis: {
default: {
url: '', // <- should be empty string, not '/'
// ...
},
},
} as Config.Environment;
```

2
framework/src/Volo.Abp.Cli.Core/Volo/Abp/Cli/ProjectBuilding/Templates/App/AppTemplateBase.cs

@ -139,7 +139,7 @@ namespace Volo.Abp.Cli.ProjectBuilding.Templates.App
steps.Add(new ChangePublicAuthPortStep()); steps.Add(new ChangePublicAuthPortStep());
} }
if (context.BuildArgs.DatabaseProvider != DatabaseProvider.NotSpecified || context.BuildArgs.DatabaseProvider != DatabaseProvider.EntityFrameworkCore) if (context.BuildArgs.DatabaseProvider != DatabaseProvider.NotSpecified && context.BuildArgs.DatabaseProvider != DatabaseProvider.EntityFrameworkCore)
{ {
steps.Add(new RemoveEfCoreDependencyFromPublicStep()); steps.Add(new RemoveEfCoreDependencyFromPublicStep());
} }

Loading…
Cancel
Save