aboutsummaryrefslogtreecommitdiffstats
path: root/actionpack/lib/action_dispatch/middleware/session/abstract_store.rb
Commit message (Collapse)AuthorAgeFilesLines
* stop using deprecated Abstract::ID classAaron Patterson2015-09-041-1/+1
|
* use a request object in the session middlewareAaron Patterson2015-08-221-4/+8
| | | | | This commit allows us to use one request object rather than allocating multiple request objects to deal with the session.
* Use Encoding::UTF_8 constant :do_not_litter:Akira Matsuda2013-01-281-1/+1
|
* Revert cb3181e - no longer required.Mark J. Titorenko2013-01-081-2/+0
|
* Avoid Rack security warning no secret providedSantiago Pastorino2013-01-081-0/+2
| | | | This avoids "SECURITY WARNING: No secret option provided to Rack::Session::Cookie."
* load active_support/core_ext/object/blank in active_support/railsXavier Noria2012-08-021-1/+0
|
* session creation methods to a moduleAaron Patterson2012-05-041-6/+9
|
* bread AD::Request::Session to it's own file, consolidate HASH OF DOOM lookupsAaron Patterson2012-05-031-150/+1
|
* extract options finding to a methodAaron Patterson2012-05-021-4/+7
|
* testing session store behaviorAaron Patterson2012-05-021-7/+19
|
* initialize instance variablesAaron Patterson2012-05-021-6/+5
|
* converted session hash to delegationAaron Patterson2012-05-021-21/+19
|
* session hash importedAaron Patterson2012-05-021-15/+111
|
* oops, forgot some semicolonsAaron Patterson2012-05-021-3/+3
|
* remove unused ivarAaron Patterson2012-05-021-4/+3
|
* use hash fetches to populate the :id valueAaron Patterson2012-05-021-12/+7
|
* imported options, switched to object compositionAaron Patterson2012-05-021-13/+56
|
* * move exception message to exception constructorAaron Patterson2012-05-021-5/+11
| | | | | * save original exception * keep original backtrace
* Support cookie jar options for all cookie storesbrainopia2012-04-301-0/+7
|
* remove checks for encodings availabilitySergey Nartimov2011-12-251-1/+1
|
* Get rid of the close checks since we cannot reliably close the session anyway.José Valim2011-12-161-4/+0
|
* Split long string into multiple shorter ones Daniel Schierbeck2011-08-291-1/+4
| | | This makes the code more readable.
* removed deprecated methods, and related tests, from ActionPackJosh Kalderimis2011-05-241-7/+1
|
* Replace references to ActiveSupport::SecureRandom with just SecureRandom, ↵Jon Leighton2011-05-231-1/+1
| | | | and require 'securerandom' from the stdlib when active support is required.
* generated session ids should be encoded as UTF-8Aaron Patterson2011-04-141-1/+3
|
* Initialize sid should just skip instance variables.José Valim2010-10-041-0/+7
|
* Rely on Rack::Session stores API for more compatibility across the Ruby world.José Valim2010-10-031-231/+49
|
* no need to check for nil?Neeraj Singh2010-09-301-1/+1
|
* Remove more warnings on AP.Emilio Tagua2010-09-281-2/+2
|
* Only send secure cookies over SSL.W. Andrew Loe III2010-09-131-1/+4
|
* Revert "Avoid uneeded queries in session stores if sid is not given."José Valim2010-07-291-5/+2
| | | | | | First step to merge Rails and Rack session stores. Rack always expects to receive the SID since it may have different behavior if the SID is nil. This reverts commit e210895ba95e498b9debbf43a3e5ae588bca81f0.
* Set session options id to nil is respected and cancels lazy loading.José Valim2010-07-181-2/+2
|
* Avoid uneeded queries in session stores if sid is not given.José Valim2010-07-181-2/+5
|
* porting session.clear fix to master branch. [#5030 state:resolved]Aaron Patterson2010-07-011-0/+5
| | | | Signed-off-by: Jeremy Kemper <jeremy@bitsweat.net>
* Fixed that an ArgumentError is thrown when request.session_options[:id] is ↵Michael Lovitt2010-06-271-32/+32
| | | | | | | | read in the following scenario: when the cookie store is used, and the session contains a serialized object of an unloaded class, and no session data accesses have occurred yet. Pushed the stale_session_check responsibility out of the SessionHash and down into the session store, closer to where the deserialization actually occurs. Added some test coverage for this case and others related to deserialization of unloaded types. [#4938] Signed-off-by: José Valim <jose.valim@gmail.com>
* Do not mark the session as loaded if an error happened while doing it.José Valim2010-06-251-2/+1
|
* Calling exists? in the session store, without checking for stale sessions, ↵José Valim2010-06-251-1/+4
| | | | was causing the cookie store to panic because we need to unpack the whole session to get its key. This commit fixes this issue and also caches exists calls for performance improvements.
* Make sure that Rails doesn't resent session_id cookie over and over again if ↵Prem Sichanugrist2010-06-251-1/+3
| | | | | | | | it's already there [#2485 state:resolved] This apply to only Active Record store and Memcached store, as they both store only the session_id, which will be unchanged, in the cookie. Signed-off-by: José Valim <jose.valim@gmail.com>
* Avoid deserializing cookies too early, which causes session objects to not ↵José Valim2010-06-241-17/+16
| | | | be available yet. Unfortunately, could not reproduce this in a test case.
* Sessions should not be created until written to and session data should be ↵Michael Lovitt2010-06-231-11/+85
| | | | | | | | destroyed on reset. [#4938] Signed-off-by: Jeremy Kemper <jeremy@bitsweat.net>
* Took out the domain option logic to cookies.rb.Rizwan Reza2010-06-111-12/+0
|
* Moved Domain regexp to a constant and added comments.Rizwan Reza2010-06-111-1/+8
|
* The previous commit didn't work with complex domains, which is now fixed.Rizwan Reza2010-06-111-4/+4
|
* Add support for multi-subdomain session by setting cookie host in session ↵Rizwan Reza2010-06-111-1/+6
| | | | | | cookie so you can share session between www.example.com, example.com and user.example.com. [#4818 state:resolved] This reverts commit 330a89072a493aafef1e07c3558964477f85adf0.
* Stop the flash middleware from forcibly loading sessions even if the user ↵wycats2010-06-041-4/+4
| | | | doesn't use sessions at all
* Cut the fat and make session stores rely on request.cookie_jar and change ↵José Valim2010-05-181-45/+37
| | | | set_session semantics to return the cookie value instead of a boolean.
* Remove deprecated methods since 2-3-stable.José Valim2010-05-181-34/+6
|
* adds missing requires for Object#blank? and Object#present?Xavier Noria2010-03-281-0/+1
|
* Fix const reference for SessionRestoreErrorJoshua Peek2010-01-151-1/+1
|
* All AD modules are "deferrable"Joshua Peek2009-12-221-0/+1
|