We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Currently the Rails API doesn't do any CSRF checking (i.e. protect_from_forgery), but it should.
protect_from_forgery
This could presumably be done by adding something like:
class ApplicationController < ActionController::API include ActionController::RequestForgeryProtection before_action :csrf_token_valid? after_action :set_csrf_cookie protected def set_csrf_cookie cookies['X-CSRF-Token'] = form_authenticity_token end def csrf_token_valid? Rails.env != 'production' || request.headers['X-CSRF-Token'] === cookies['X-CSRF-Token'] end end
The text was updated successfully, but these errors were encountered:
No branches or pull requests
Currently the Rails API doesn't do any CSRF checking (i.e.
protect_from_forgery
), but it should.This could presumably be done by adding something like:
The text was updated successfully, but these errors were encountered: