mirror of
https://github.com/inverse-inc/sogo.git
synced 2026-10-06 04:20:33 +00:00
(feat) added AngularJS's XSRF support (#3246)
This commit is contained in:
@@ -455,8 +455,8 @@
|
||||
|
||||
- (id <WOActionResults>) logoffAction
|
||||
{
|
||||
SOGoWebAuthenticator *auth;
|
||||
NSString *userName, *value;
|
||||
SOGoWebAuthenticator *auth;
|
||||
WOResponse *response;
|
||||
NSCalendarDate *date;
|
||||
WOCookie *cookie;
|
||||
@@ -486,6 +486,12 @@
|
||||
if (cookie)
|
||||
[response addCookie: cookie];
|
||||
|
||||
// We remove the XSRF cookie
|
||||
cookie = [WOCookie cookieWithName: @"XSRF-TOKEN" value: @"discard"];
|
||||
[cookie setPath: [NSString stringWithFormat: @"/%@/", [[context request] applicationName]]];
|
||||
[cookie setExpires: [date yesterday]];
|
||||
[response addCookie: cookie];
|
||||
|
||||
[response setHeader: [date rfc822DateString] forKey: @"Last-Modified"];
|
||||
[response setHeader: @"no-store, no-cache, must-revalidate,"
|
||||
@" max-age=0, post-check=0, pre-check=0"
|
||||
|
||||
Reference in New Issue
Block a user