Peter Jones
2a986200b9
Bug: Earlier Check for Session in Forgery Protection
...
The session is used by the form_authenticity_token method before it is
tested to be valid. This patch moves a few lines around so that the
session is validated first.
Without this patch, if you try to use forgery protection with sessions
turned off, you get this exception message:
undefined method `session_id' for {}:Hash
The patch includes a test that can be used to see this behavior before
the request_forgery_protection.rb file is patched to fix it.
2008-05-11 13:27:34 -05:00
..
2006-06-01 15:42:08 +00:00
2008-01-05 13:32:06 +00:00
2008-03-28 19:45:32 +00:00
2008-04-29 15:12:47 -04:00
2008-01-05 13:32:06 +00:00
2008-01-05 13:32:06 +00:00
2008-04-28 10:52:23 -07:00
2008-05-05 23:42:52 -07:00
2008-01-05 13:32:06 +00:00
2008-04-19 16:21:34 -05:00
2008-01-05 13:32:06 +00:00
2008-02-02 02:55:44 +00:00
2008-01-05 13:32:06 +00:00
2008-01-05 13:32:06 +00:00
2008-04-19 18:59:13 +01:00
2008-04-19 16:21:18 +01:00
2008-04-18 13:05:43 +01:00
2008-01-19 05:24:44 +00:00
2008-04-01 00:50:09 +00:00
2008-01-05 13:32:06 +00:00
2008-03-23 01:48:17 +00:00
2008-04-19 18:59:13 +01:00
2008-01-11 06:39:56 +00:00
2008-04-06 18:42:34 +00:00
2008-01-05 13:32:06 +00:00
2008-02-19 21:43:13 +00:00
2008-04-01 06:11:48 +00:00
2008-04-19 18:59:13 +01:00
2008-04-19 18:59:13 +01:00
2008-05-01 17:45:14 -04:00
2008-05-06 12:02:24 +01:00
2008-04-11 12:34:44 -05:00
2008-05-10 11:28:19 +01:00
2008-04-02 12:48:59 +00:00
2008-05-01 10:21:46 +01:00
2008-05-11 13:27:34 -05:00
2008-04-08 05:05:54 +00:00
2008-04-19 18:59:13 +01:00
2008-05-06 21:48:07 +12:00
2008-05-10 14:55:41 +12:00
2008-01-05 13:32:06 +00:00
2008-01-11 22:07:04 +00:00
2008-01-05 13:32:06 +00:00
2008-05-11 13:18:49 -05:00
2008-05-11 18:30:10 +12:00
2008-02-18 00:42:06 +00:00
2008-01-05 13:32:06 +00:00
2008-01-21 20:45:04 +00:00
2008-02-27 23:11:08 +00:00