This project is archived and is in readonly mode.
UJS silently fails when csrf_meta_tag is not present
-
Kieran P
- Tag set to ujs
-
José Valim
Please provide a patch!
-
Steve St. Martin
- Tag changed from ujs to patch, ujs
resolved for jquery-ujs with commit http://github.com/rails/jquery-ujs/commit/ac78a119772f2d1bb495ff2b9..., patch provided for prototype-ujs
-
Kieran P
Actually José, it isn't fixed on the master yet: http://github.com/rails/rails/blob/master/railties/lib/rails/genera...
-
José Valim
Sorry, I completely misread the ticket.
At first, it was announcing when csrf_meta_tag was not present. But this was changed, because you may disable csrf protection in some pages and the javascript code should work anyway. So the current JS code is correct.
But I know it's a pain in the ass that it fails silently. Maybe we should try to do something in the Ruby side. For instance, whenever csrf protection is enabled but the user do not add call csrf_meta_tag, we could print a warning.
Ideas are welcome. :)
-
José Valim
- State changed from resolved to open
- Assigned user changed from josh to José Valim
- Milestone cleared.
-
Steve St. Martin
I think this only really applies to links that have data-method other then GET, as form_for will create the token. Currently in the jQuery driver I'm only solving the most common use case of link_to :method => :delete with an exception as its part of the scaffolded code.
Keeping an eye on this so we can solve it in a consistent manner.
-
José Valim
I agree this is an issue, but I still disagree with the solution. The JS drivers should not enforce CSRF because Rails does not do so.
-
Dan Pickett
- Tag changed from patch, ujs to bugmash, patch, ujs
-
Rizwan Reza
- Tag changed from bugmash, patch, ujs to patch, ujs
- State changed from open to invalid
