Sha256: fdbc484b9d1c9e6106d6eb8fe7c443c58f8cda3e747509069244dd649f110982
Contents?: true
Size: 594 Bytes
Versions: 27
Compression:
Stored size: 594 Bytes
Contents
require 'rack/protection' module Rack module Protection ## # Prevented attack:: CSRF # Supported browsers:: all # More infos:: http://en.wikipedia.org/wiki/Cross-site_request_forgery # # Only accepts unsafe HTTP requests if a given access token matches the token # included in the session *or* the request comes from the same origin. # # Compatible with rack-csrf. class RemoteToken < AuthenticityToken default_reaction :deny def accepts?(env) super or referrer(env) == Request.new(env).host end end end end
Version data entries
27 entries across 24 versions & 4 rubygems