Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

UJS silently fails when csrf_meta_tag is not present

#4084

The current Rails UJS files fail silently for things like link_to ..., :method => :delete, :confirm => 'Are you sure? when the tag for csrf_meta_tag is not sent. Since it is required, it really should throw an alert if the tag is not found, rather than confusing us poor people :-P

reference: http://www.themodestrubyist.com/2010/02/24/rails-3-ujs-and-csrf-met...

Reported by Kieran P · March 2nd, 2010 @ 03:40 AM

State: invalid
Milestone: 3.0.2
Assigned to: José Valim José Valim
Importance: Low

Activity

  1. Kieran P
  2. José Valim
    José Valim

    Please provide a patch!

    March 3rd, 2010 @ 09:07 AM

  3. Steve St. Martin
    Steve St. Martin
    • Tag changed from ujs to patch, ujs

    resolved for jquery-ujs with commit http://github.com/rails/jquery-ujs/commit/ac78a119772f2d1bb495ff2b9..., patch provided for prototype-ujs

    April 13th, 2010 @ 04:57 PM

  4. Steve St. Martin
    Steve St. Martin
    • Assigned user set to josh

    assigning to josh for commit to prototype driver

    April 15th, 2010 @ 02:59 PM

  5. José Valim
    José Valim
    • State changed from new to resolved

    This is fixed on master.

    April 15th, 2010 @ 06:11 PM

  6. Kieran P
  7. José Valim
    José Valim

    Sorry, I completely misread the ticket.

    At first, it was announcing when csrf_meta_tag was not present. But this was changed, because you may disable csrf protection in some pages and the javascript code should work anyway. So the current JS code is correct.

    But I know it's a pain in the ass that it fails silently. Maybe we should try to do something in the Ruby side. For instance, whenever csrf protection is enabled but the user do not add call csrf_meta_tag, we could print a warning.

    Ideas are welcome. :)

    April 15th, 2010 @ 08:34 PM

  8. José Valim
    José Valim
    • State changed from resolved to open
    • Assigned user changed from josh to José Valim
    • Milestone cleared.

    April 15th, 2010 @ 08:54 PM

  9. Steve St. Martin
    Steve St. Martin

    I think this only really applies to links that have data-method other then GET, as form_for will create the token. Currently in the jQuery driver I'm only solving the most common use case of link_to :method => :delete with an exception as its part of the scaffolded code.

    Keeping an eye on this so we can solve it in a consistent manner.

    April 15th, 2010 @ 09:52 PM

  10. José Valim
    José Valim

    I agree this is an issue, but I still disagree with the solution. The JS drivers should not enforce CSRF because Rails does not do so.

    April 18th, 2010 @ 06:52 AM

  11. Dan Pickett
    Dan Pickett
    • Tag changed from patch, ujs to bugmash, patch, ujs

    May 15th, 2010 @ 01:49 AM

  12. Rizwan Reza
    Rizwan Reza
    • Tag changed from bugmash, patch, ujs to patch, ujs
    • State changed from open to invalid

    May 15th, 2010 @ 10:19 AM

  13. Jeremy Kemper
    Jeremy Kemper
    • Milestone set to 3.0.2
    • Importance changed from to Low

    October 15th, 2010 @ 11:01 PM