#321 √ incomplete
Michael Trim

Add :protect_against_forgery option to form_tag

Reported by Michael Trim | June 3rd, 2008 @ 08:05 PM

This patch adds an option to prevent the CSRF (Cross-Site Request Forgery) protection token being included for an individual form, whilst still having the forgery protection enabled.

This is intented only for situations where the form is being submitted to a third-party (e.g. an external search). In such cases, CSRF protection is not needed and revealing the token to the third party is a security risk as they could then submit requests as the user.

Passes existing tests and adds one new test.

Comments and changes to this ticket

  • Pratik

    Pratik June 5th, 2008 @ 10:16 PM

    • → State changed from “new” to “incomplete”
    • → Assigned user changed from “” to “Pratik”

    I think the option should be ":protect_against_forgery => false" to be consistent with the rest of the stuff. Could you please upload a new patch with that ?

    Cheers.

  • Michael Trim

    Michael Trim June 6th, 2008 @ 02:35 AM

    • → Title changed from “Add :no_csrf_token option to form_tag” to “Add :protect_against_forgery option to form_tag”

    Updated patch attached, although thinking about it a bit more I'm not sure whether this is worth the bother since one can easily write the html directly.

Please Login or create a free account to add a new comment.

You can update this ticket by sending an email to from your email client. (help)

Create your profile

Help contribute to this project by taking a few moments to create your personal profile. Create your profile »

Source available from github

Repository is at http://github.com/rails/rails

Check out the development master (Edge Rails):

git clone git://github.com/rails/rails.git

Creating or reviewing a patch

See the contributor guide.

Creating a feature request

Please don't. If you want a new feature in Rails, you'll have to pull up your sleeves and get busy yourself. Or convince someone else to do it. See the contributor guide on how to get going. But posting them here is just going to lead to ticket root.

Creating a bug report

When creating a bug report, be sure to include as much relevant information as possible. Post the code sample that causes the problem. Preferably, alter the unit tests and show through either changed or added tests how the expected behavior is not occuring.

Security vulnerabilities should be reported via an email to security@rubyonrails.org, do not use trac for reporting security vulnerabilities. All content in trac is publicly available as soon as it is posted.

Then don't get your hopes up. Unless you have a "Code Red, Mission Critical, The World is Coming to an End" kinda bug, you're creating this ticket in the hope that others with the same problem will be able to collaborate with you on solving it. Do not expect that the ticket automatically will see any activity or that others will jump to fix it. Creating a ticket like this is mostly to help yourself start on the path of fixing the problem and for others to sign on to with a "I'm having this problem too"..

Shared Ticket Bins

People watching this ticket