feat(security): Automatic XSRF handling.

Automatically recognize XSRF protection cookies, and set a corresponding XSRF
header. Allows applications to configure the cookie names, or if needed,
completely override the XSRF request configuration by binding their own
XSRFHandler implementation.

Part of #8511.
This commit is contained in:
Martin Probst
2016-05-27 20:15:40 -07:00
parent 3ae29c08ac
commit 4d793c4eb8
10 changed files with 195 additions and 22 deletions

View File

@ -442,6 +442,7 @@ var HTTP: string[] = [
'BrowserXhr',
'Connection',
'ConnectionBackend',
'CookieXSRFStrategy',
'HTTP_BINDINGS',
'HTTP_PROVIDERS',
'Headers',
@ -460,7 +461,8 @@ var HTTP: string[] = [
'ResponseType',
'URLSearchParams',
'XHRBackend',
'XHRConnection'
'XHRConnection',
'XSRFStrategy',
];
var HTTP_TESTING: string[] = ['MockBackend', 'MockConnection'];