diff options
Diffstat (limited to 'actionpack/test')
-rw-r--r-- | actionpack/test/controller/request_forgery_protection_test.rb | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/actionpack/test/controller/request_forgery_protection_test.rb b/actionpack/test/controller/request_forgery_protection_test.rb index 4fcdc7ed4a..d0c3c6e224 100644 --- a/actionpack/test/controller/request_forgery_protection_test.rb +++ b/actionpack/test/controller/request_forgery_protection_test.rb @@ -22,6 +22,10 @@ module RequestForgeryProtectionActions render :inline => "<%= button_to('New', '/') {} %>" end + def remote_form + render :inline => "<% form_remote_tag(:url => '/') {} %>" + end + def unsafe render :text => 'pwn' end @@ -75,6 +79,11 @@ module RequestForgeryProtectionTests assert_select 'form>div>input[name=?][value=?]', 'authenticity_token', @token end + def test_should_render_remote_form_with_only_one_token_parameter + get :remote_form + assert_equal 1, @response.body.scan(@token).size + end + def test_should_allow_get get :index assert_response :success |