News & Updates

How to Disable CSRF in Spring Security XML – A Quick Guide

By Erica Hollis 9 min read 4748 views

How to Disable CSRF in Spring Security XML – A Quick Guide

Cross‑Site Request Forgery (CSRF) is a classic web‑security threat, and Spring Security enables protection for you out of the box. However, there are legitimate scenarios—such as stateless REST APIs or internal services—where you might want to disable CSRF in Spring Security XML. This short guide walks you through the why, the when, and the exact XML snippet you need, plus a few safety tips.

Why CSRF Matters in Spring Applications

CSRF exploits the trust a browser has in a logged‑in user. An attacker tricks the user’s browser into sending a forged request to a protected endpoint, potentially causing unwanted state changes. Spring’s CSRF filter mitigates this by requiring a hidden token on state‑changing requests (POST, PUT, DELETE, etc.). When the token is missing or mismatched, the request is rejected.

When Disabling CSRF Might Be Acceptable

Turning off the filter isn’t a decision to take lightly. Consider disabling CSRF only if:

  • Your application is purely a stateless JSON API accessed via tokens (e.g., JWT) rather than sessions.

If any of these conditions are uncertain, keep CSRF enabled and look for alternative solutions.

Step‑by‑Step: Disabling CSRF in XML

The XML configuration for Spring Security is straightforward. Locate the <http> element that defines your security filter chain and add the csrf sub‑element with disabled="true". Here’s a minimal example:

<!-- src/main/webapp/WEB-INF/spring-security.xml -->

<beans:beans xmlns="http://www.springframework.org/schema/security"

xmlns:beans="http://www.springframework.org/schema/beans"

xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:schemaLocation="

http://www.springframework.org/schema/security

http://www.springframework.org/schema/security/spring-security-5.8.xsd

http://www.springframework.org/schema/beans

http://www.springframework.org/schema/beans/spring-beans.xsd">

<http pattern="/api/**" create-session="stateless">

<intercept-url pattern="/api/public/**" access="permitAll"/>

<intercept-url pattern="/api/**" access="isAuthenticated()"/>

<csrf disabled="true"/> <!-- Disable CSRF for this filter chain -->

<custom-filter ref="myAuthenticationFilter" after="BASIC_AUTH_FILTER"/>

</http>

<authentication-manager>

<authentication-provider ref="myUserDetailsService"/>

</authentication-manager>

</beans:beans>

Key points to notice:

  • The pattern attribute limits the configuration to the API path; you can keep CSRF enabled for the rest of the site by defining another <http> element without the csrf disabled line.
  • create-session="stateless" tells Spring not to create an HTTP session, which aligns with typical token‑based authentication.
  • Place the csrf tag directly under <http>; any misplaced closing tag will cause the context to fail on startup.

Testing the Configuration

After updating the XML, restart your application and run a quick curl test:

curl -X POST http://localhost:8080/api/resource \

-H "Content-Type: application/json" \

-d '{"name":"test"}' -v

If CSRF is truly disabled, the server should respond with a 200 or whatever business logic you’ve defined, rather than a 403 “Forbidden” error indicating a missing CSRF token. Also, verify that non‑API endpoints still enforce CSRF by sending a POST request to a regular form page; you should still see the 403 if the token is absent.

Alternatives to Turning Off CSRF

Before you commit to disabling the filter, explore these options:

  • Stateless CSRF token handling: Use CookieCsrfTokenRepository to store the token in a cookie, which works nicely with SPA frameworks.
  • Separate filter chains: Keep CSRF on for UI pages and disable only for API routes, as shown in the example above.
  • Custom request matcher: Implement a RequestMatcher that bypasses CSRF for specific HTTP methods or endpoints while leaving the rest protected.

These approaches preserve the safety net that CSRF protection offers without sacrificing the convenience of token‑based APIs.

Common Pitfalls and How to Avoid Them

Even a tiny typo can break the whole security chain. Watch out for:

  • Missing the closing /> on the csrf tag, which leads to a bean‑creation exception.
  • Defining multiple <http> elements with overlapping pattern attributes; Spring will apply the first matching chain, potentially leaving CSRF enabled where you thought it wasn’t.
  • Relying on the default sessionCreationPolicy when you intend a stateless API; without create-session="stateless", Spring may still create a session and store a CSRF token there.

Running the application with the --debug flag (or checking the logs for “CSRF disabled”) can quickly confirm the intended behavior.

FAQ

Is it safe to disable CSRF for all endpoints?

Generally no. Disabling CSRF across the board opens your site to forgery attacks from any browser that a user might have logged into. Limit the disabling to stateless APIs or internal services where you control the client.

Do I need to change anything else after disabling CSRF?

Usually you’ll also want to set sessionCreationPolicy="stateless" for the same filter chain, and make sure your authentication mechanism (e.g., JWT) validates each request independently.

Can I re‑enable CSRF without restarting the server?

Spring’s XML configuration is loaded at context startup, so changes require a restart or a redeploy of the application.

What’s the difference between csrf disabled="true" and removing the csrf element entirely?

Leaving out the element keeps the default behavior, which is enabled. Explicitly setting disabled="true" tells Spring to turn the filter off, making the intention clear to anyone reading the config.

SOLUTION: Spring security quick guide - Studypool
Spring Security - How to Enable and Disable CSRF - GeeksforGeeks
Spring Boot Disable Csrf _ Spring Security Csrf – ZZGH
Disable CSRF using property `security.enable-csrf` · Issue #11170 ...

Written by Erica Hollis

Erica Hollis is a News Correspondent covering technology, society, and the changing landscape of everyday life. Her work explores the connections between innovation and public interest, translating complex developments into accessible reporting while examining their opportunities, challenges, and lasting effects.


You Might Like