Description
Settings such as csrf().disable(), frameOptions().disable() and anyRequest().permitAll() disable protections or access restrictions in the applicable Spring Security filter chain. The risk depends on automatically sent browser credentials, other framing restrictions and which requests the chain handles.
Potential impact
- Without CSRF protection, an external site may trigger state changes when the browser automatically sends credentials such as cookies.
- Disabling
frameOptionsmay weaken clickjacking protection. anyRequest().permitAll()does not require authentication for requests handled by that chain and may expose functions that should be protected.
Remediation
- Review the browser authentication mechanism and retain CSRF protection. Explicitly exclude only endpoints that do not need it;
csrf().disable()applies to the whole chain. - Use
sameOriginor a suitable CSPframe-ancestorspolicy instead of simply removing framing restrictions. - Permit only intended public routes and require authentication elsewhere.
Examples
These are Spring Security 6.x configuration excerpts. Register the configuration class and configure authentication separately, using the DSL appropriate to your installed version.
Before
java
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;
public class UnsafeCsrfConfig {
@Bean
SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http.csrf().disable();
return http.build();
}
}
After
java
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;
public class SafeSecurityConfig {
@Bean
SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(auth -> auth
.requestMatchers("/health").permitAll()
.anyRequest().authenticated()
);
return http.build();
}
}
Explanation:
- Before: Disables CSRF protection in this filter chain.
- After: Retains default CSRF protection, allows
/healthwithout authentication and requires authentication for other requests. Configure role- and object-level authorization separately.
Review other protection settings
Check framing restrictions and broad request permissions against the intended design. In both the Java and Kotlin DSLs, retain the necessary protections and allow only the intended public routes.