By mswatcher
via metaskills.net
Published: Apr 14 2010 / 09:14
A while back ago I wrote an article about how to use Rails built-in forgery protection in your RESTful AJAX calls. Normally AJAX requests, those responding true to request.xhr? in rails, are forgery whitelisted. But sometimes, and under what conditions I am not sure, AJAX methods are subjected to forgery protection. Maybe you have the ActionDispatch::Request#forgery_whitelisted? overridden to not include AJAX requests? Either way and for whatever reason
Add your comment
Voters For This Link (10)
-
mswatcher -
cdKexin -
yrsmile -
agnihotrived -
alireza.haghighatkhah@gmail.com -
mosessaur -
aclarke -
javamac2009 -
freepostia -
zis