aboutsummaryrefslogtreecommitdiffstats
path: root/actionpack/test/controller
diff options
context:
space:
mode:
authorSantiago Pastorino <santiago@wyeworks.com>2014-03-08 15:22:42 -0200
committerSantiago Pastorino <santiago@wyeworks.com>2014-03-08 15:22:42 -0200
commit2af7a7b19cd7735530f5fd4762896694f5955051 (patch)
tree9324445c7bd58aa3d53ed5a5a2e7dd92bb7f9652 /actionpack/test/controller
parentdc8bfc8ab62c3e3a776297226ef43027bc7d09c1 (diff)
parent67584c6ae37c88f8abba6f4fbdeedc7c1a6dfa1b (diff)
downloadrails-2af7a7b19cd7735530f5fd4762896694f5955051.tar.gz
rails-2af7a7b19cd7735530f5fd4762896694f5955051.tar.bz2
rails-2af7a7b19cd7735530f5fd4762896694f5955051.zip
Merge pull request #14280 from joho/make_csrf_failure_logging_optional
Make CSRF failure logging optional/configurable.
Diffstat (limited to 'actionpack/test/controller')
-rw-r--r--actionpack/test/controller/request_forgery_protection_test.rb16
1 files changed, 16 insertions, 0 deletions
diff --git a/actionpack/test/controller/request_forgery_protection_test.rb b/actionpack/test/controller/request_forgery_protection_test.rb
index 1f5fc06410..99229b3baf 100644
--- a/actionpack/test/controller/request_forgery_protection_test.rb
+++ b/actionpack/test/controller/request_forgery_protection_test.rb
@@ -289,6 +289,22 @@ module RequestForgeryProtectionTests
end
end
+ def test_should_not_warn_if_csrf_logging_disabled
+ old_logger = ActionController::Base.logger
+ logger = ActiveSupport::LogSubscriber::TestHelper::MockLogger.new
+ ActionController::Base.logger = logger
+ ActionController::Base.log_warning_on_csrf_failure = false
+
+ begin
+ assert_blocked { post :index }
+
+ assert_equal 0, logger.logged(:warn).size
+ ensure
+ ActionController::Base.logger = old_logger
+ ActionController::Base.log_warning_on_csrf_failure = true
+ end
+ end
+
def test_should_only_allow_same_origin_js_get_with_xhr_header
assert_cross_origin_blocked { get :same_origin_js }
assert_cross_origin_blocked { get :same_origin_js, format: 'js' }