aboutsummaryrefslogtreecommitdiffstats
path: root/guides/source/upgrading_ruby_on_rails.md
diff options
context:
space:
mode:
authorEileen M. Uchitelle <eileencodes@gmail.com>2015-09-16 07:56:32 -0400
committerEileen M. Uchitelle <eileencodes@gmail.com>2015-09-16 07:56:32 -0400
commit3edc7f7a1ce39a63828ecb7488dcedc188aa23f9 (patch)
treee221131d992a55b8443390d08d248c5bc57dc966 /guides/source/upgrading_ruby_on_rails.md
parent93181210234411b9a918cca481422eabebe5400e (diff)
parent570cd2481653be3d5bc8962b4b95360c6569041b (diff)
downloadrails-3edc7f7a1ce39a63828ecb7488dcedc188aa23f9.tar.gz
rails-3edc7f7a1ce39a63828ecb7488dcedc188aa23f9.tar.bz2
rails-3edc7f7a1ce39a63828ecb7488dcedc188aa23f9.zip
Merge pull request #21618 from designgrill/master
Improved explanation of the <script> tag CSRF behavior
Diffstat (limited to 'guides/source/upgrading_ruby_on_rails.md')
-rw-r--r--guides/source/upgrading_ruby_on_rails.md6
1 files changed, 2 insertions, 4 deletions
diff --git a/guides/source/upgrading_ruby_on_rails.md b/guides/source/upgrading_ruby_on_rails.md
index 30c0fcb294..2de9d6045e 100644
--- a/guides/source/upgrading_ruby_on_rails.md
+++ b/guides/source/upgrading_ruby_on_rails.md
@@ -316,11 +316,9 @@ Upgrading from Rails 4.0 to Rails 4.1
Or, "whaaat my tests are failing!!!?"
-Cross-site request forgery (CSRF) protection now covers GET requests with
-JavaScript responses, too. This prevents a third-party site from referencing
-your JavaScript URL and attempting to run it to extract sensitive data.
+Cross-site request forgery (CSRF) protection now covers GET requests with dynamic JavaScript responses, too. By default, all javascript responses generated by an action will be blocked for non xhr requests. This will block usage of such urls in any `<script>` tag including your own. That way, in a possible attack scenario, it prevents a third-party site from referencing your JavaScript URL and attempting to run it to extract sensitive data.
-This means that your functional and integration tests that use
+It also means that your functional and integration tests that use
```ruby
get :index, format: :js