GET requests don't get any CSRF protection by Rails, thus these sensitive actions should be better protected. Thanks to @tomekr for the report. |
||
|---|---|---|
| .. | ||
| edit.html.haml | ||
| edit.mobile.haml | ||
| export_email.markerb | ||
| export_failure_email.markerb | ||
| export_photos_email.markerb | ||
| export_photos_failure_email.markerb | ||
| getting_started.haml | ||
| getting_started.mobile.haml | ||
| privacy_settings.html.haml | ||
| public.atom.builder | ||