CSRF protection

#5 · closed · 0 comments

View on GitHub ↗

ysbaddaden

Controller actions should be protected against Cross-site request forgery (following Rails API). - A secret must be shared from the user session and HTML templates (inject `csrf_param` and `csrf_token` HTML meta + inject secret into all generated forms). - Allow token to be present as a POST body param (`csrf_param`) or the `X-CSRF-Token` header. - Requests with a valid secret shall be processed normally. - Requests with a missing or wrong secret must be cancelled immediately, and the session destroyed. - The protection must be skippable (eg: API) by defining `def csrf_protection_enabled?; false; end` (for example). - GET requests always skip CSRF verification.

Comments