<para>For passivity reasons, if you are using the XML configuration, CSRF protection must be explicitly enabled using the <linklinkend="nsa-csrf"><csrf></link> element. Refer to the
<linklinkend="nsa-csrf"><csrf></link> element's documentation for additional customizations.</para>
<note>
<para><linkxlink:href="https://jira.springsource.org/browse/SEC-2347">SEC-2347</link> is logged to ensure Spring
Security 4.x's XML namespace configuration will enable CSRF protection by default.</para>