index
:
rails.git
3-2-stable-for-hmno
master
Mirror of official rails repo with custom fixes.
Harald Eilertsen
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
actionpack
/
lib
/
action_controller
/
metal
/
request_forgery_protection.rb
Commit message (
Expand
)
Author
Age
Files
Lines
*
Add prepend option to protect_from_forgery.
Josef Šimánek
2015-01-08
1
-1
/
+8
*
Improve protect_from_forgery documentation. [ci skip].
Josef Šimánek
2015-01-06
1
-3
/
+3
*
Document all options for protect_from_forgery.
Josef Šimánek
2015-01-04
1
-8
/
+2
*
Merge pull request #18102 from arthurnn/nodoc_constant
Arthur Nogueira Neves
2014-12-19
1
-0
/
+1
*
Use AS secure_compare for CSRF token comparison
Guillermo Iguaran
2014-10-23
1
-2
/
+2
*
Merge pull request #16570 from bradleybuda/breach-mitigation-mask-csrf-token
Jeremy Kemper
2014-08-19
1
-3
/
+65
|
\
|
*
Auth token mask from breach-mitigation-rails gem
Bradley Buda
2014-08-19
1
-3
/
+65
*
|
Uppercase HTML in docs.
Hendy Tanata
2014-08-08
1
-2
/
+2
|
/
*
Fix protect_from_forgery docs
David Albert
2014-07-27
1
-1
/
+1
*
Moved 'params[request_forgery_protection_token]' into its own method and impr...
Tom Kadwill
2014-05-06
1
-1
/
+1
*
Make CSRF failure logging optional/configurable.
John Barton (joho)
2014-03-05
1
-1
/
+7
*
Clearly limit new CSRF protection to GET requests
Jeremy Kemper
2013-12-17
1
-2
/
+7
*
CSRF protection from cross-origin <script> tags
Jeremy Kemper
2013-12-17
1
-13
/
+61
*
NullSessionHash#destroy should be a no-op
Jonathan Baudanza
2013-09-18
1
-0
/
+3
*
[ci skip] document protect_against_forgery? method
Weston Platter
2013-05-10
1
-0
/
+1
*
This cache is not needed
Santiago Pastorino
2013-02-21
1
-2
/
+1
*
Use composition to figure out the forgery protection strategy
Santiago Pastorino
2013-02-21
1
-9
/
+27
*
Fix #9168 Initialize NullCookieJar with all options needed for KeyGenerator
Andrey Chernih
2013-02-08
1
-1
/
+1
*
Merge pull request #9032 from firmhouse/head-breaks-csrf
Santiago Pastorino
2013-01-28
1
-2
/
+2
|
\
|
*
Added request.head? to forgery protection code
Michiel Sikkes
2013-01-22
1
-2
/
+2
*
|
Integrate Action Pack with Rack 1.5
Carlos Antonio da Silva
2013-01-25
1
-3
/
+4
|
/
*
use `_action` instead of `_filter` callbacks
Francesco Rodriguez
2012-12-07
1
-6
/
+6
*
Sign cookies using key deriver
Santiago Pastorino
2012-11-03
1
-4
/
+4
*
Multiple changes to 1,9 hash syntax
AvnerCohen
2012-10-27
1
-3
/
+3
*
Build fix for ActionMailer
Arun Agrawal
2012-09-14
1
-0
/
+1
*
Implement :null_session CSRF protection method
Sergey Nartimov
2012-09-13
1
-22
/
+70
*
load active_support/core_ext/class/attribute in active_support/rails
Xavier Noria
2012-08-02
1
-1
/
+0
*
copy editing [ci skip]
Vijay Dev
2012-06-14
1
-4
/
+7
*
on CSRF whitelisting the argument for :if must be a symbol
Daniel Lopes
2012-06-07
1
-1
/
+1
*
fix typos on the CSRF whitelisting doc
Daniel Lopes
2012-06-07
1
-3
/
+3
*
Document the CSRF whitelisting on get requests
Daniel Lopes
2012-06-07
1
-5
/
+16
*
Removing ==Examples and last blank lines of docs from actionpack
Francesco Rodriguez
2012-05-15
1
-2
/
+0
*
CSRF messages are no longer controlled by 422.html because InvalidAuthenticit...
Tony Primerano
2012-03-28
1
-1
/
+0
*
configure how unverified request will be handled
Sergey Nartimov
2012-03-09
1
-2
/
+18
*
removed warning because logger.warn differentiate the warings
Karunakar (Ruby)
2012-01-05
1
-1
/
+1
*
Change log level for CSRF token verification warning
Mike Dillon
2011-09-10
1
-1
/
+1
*
Changed a few instances of of words in the API docs written in British Englis...
Oemuer Oezkir
2011-07-24
1
-1
/
+1
*
TODO fix explicitly loading exceptations, autoload removed
Vishnu Atrai
2011-07-11
1
-0
/
+1
*
document handle_unverified_request method
Vijay Dev
2011-07-02
1
-0
/
+2
*
update doc about resetting the session in case of authenticity token mismatch
Vijay Dev
2011-07-01
1
-6
/
+5
*
Merge branch 'master' of git://github.com/lifo/docrails
Xavier Noria
2011-05-25
1
-3
/
+3
|
\
|
*
Remove extra white spaces on ActionPack docs.
Sebastian Martinez
2011-05-23
1
-3
/
+3
*
|
Replace references to ActiveSupport::SecureRandom with just SecureRandom, and...
Jon Leighton
2011-05-23
1
-1
/
+1
|
/
*
Warn if we cannot verify CSRF token authenticity
José Valim
2011-05-09
1
-1
/
+4
*
Prepend the CSRF filter to make it much more difficult to execute application...
Michael Koziarski
2011-02-23
1
-1
/
+1
*
Change the CSRF whitelisting to only apply to get requests
Michael Koziarski
2011-02-08
1
-10
/
+9
*
Add explicit statement that verify_authenticity_token can be turned off for a...
Ryan Bigg
2010-11-27
1
-3
/
+7
*
revises implementation and documentation of csrf_meta_tags, and aliases csrf_...
Xavier Noria
2010-09-11
1
-2
/
+2
*
Revert "Setup explicit requires for files with exceptions. Removed them from ...
José Valim
2010-09-02
1
-1
/
+0
*
Setup explicit requires for files with exceptions. Removed them from autoload...
Łukasz Strzałkowski
2010-09-02
1
-0
/
+1
[next]