基本测试API认证,WebApp 认证,CSRF模块
diff --git a/src/main/resources/templates/login.html b/src/main/resources/templates/login.html
index 4feb52a..919d862 100644
--- a/src/main/resources/templates/login.html
+++ b/src/main/resources/templates/login.html
@@ -1,12 +1,15 @@
 <!DOCTYPE html>
+
 <html xmlns:th="http://www.thymeleaf.org">
 
 <head>
     <title>用户登录</title>
+    <meta name="_csrf" th:content="${_csrf.token}" />
+    <!-- default header name is X-CSRF-TOKEN -->
+    <meta name="_csrf_header" th:content="${_csrf.headerName}" />
     <link rel="stylesheet" type="text/css"  th:href="@{/static/libs/layui/css/layui.css}"   />
     <link rel="stylesheet" type="text/css"  th:href="@{/static/payapi/css/login.css}"  />
 </head>
-
 <body>
 <div class="login-wrapper">
 
@@ -25,6 +28,9 @@
                     <div class="layui-input-block">
                         <input name="username" type="text" lay-verify="required" placeholder="账号"
                                class="layui-input">
+                        <input type="hidden"
+                               th:name="${_csrf.parameterName}"
+                               th:value="${_csrf.token}"/>
                     </div>
                 </div>
                 <div class="layui-form-item">