GET requests don't get any CSRF protection by Rails, thus these sensitive actions should be better protected. Thanks to @tomekr for the report. |
||
|---|---|---|
| .. | ||
| assets | ||
| controllers | ||
| helpers | ||
| mailers | ||
| models | ||
| presenters | ||
| serializers/export | ||
| uploaders | ||
| views | ||
| workers | ||
GET requests don't get any CSRF protection by Rails, thus these sensitive actions should be better protected. Thanks to @tomekr for the report. |
||
|---|---|---|
| .. | ||
| assets | ||
| controllers | ||
| helpers | ||
| mailers | ||
| models | ||
| presenters | ||
| serializers/export | ||
| uploaders | ||
| views | ||
| workers | ||