Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Added disable_authenticity_token option to form helper

#6228

I've added disable_authenticity_token option to the form helper. So now we can generate forms without authenticity_token tag.
It is useful when we generate forms for some external resources like payments and billings where names of fields are often restricted so forms with authenticity_token are not valid.

Now we can write:

form_for(@survey, :disable_authenticity_token => true)

or:

form_tag('/', :disable_authenticity_token => true)

Reported by 2kan · December 27th, 2010 @ 04:09 PM

State: resolved
Milestone: 3.1
Assigned to: Santiago Pastorino Santiago Pastorino
Importance: Low

Activity

  1. Yaroslav Markin
    Yaroslav Markin
    • Assigned user set to José Valim

    This is basically really useful when you need to send data to a 3td party service (payment gateway, in my case) without any Rails tokens.

    December 29th, 2010 @ 04:36 PM

  2. Santiago Pastorino
    Santiago Pastorino
    • State changed from new to open
    • Milestone set to 3.1
    • Assigned user changed from José Valim to Santiago Pastorino
    • Importance changed from to Low

    Looks good can you provide docs for that? would be nice to add API docs at least

    February 3rd, 2011 @ 04:52 PM

  3. Xavier Noria
    Xavier Noria

    Would you please add some RDoc documenting this option and its rationale/real use case. Also please the guide that covers forms? All in a single (complete) patch.

    February 3rd, 2011 @ 10:04 PM

  4. Lachlan Sylvester
    Lachlan Sylvester

    Similar functionality has been added in https://rails.lighthouseapp.com/projects/8994/tickets/2988-authenti.... I am not sure that this is still needed.

    February 4th, 2011 @ 10:10 PM

  5. Dan Pickett
    Dan Pickett

    Agreed with Lachlan - this appears to be duplicated functionality that has already been committed in #2988. This ticket should be closed.

    February 4th, 2011 @ 10:24 PM

  6. Santiago Pastorino
    Santiago Pastorino

    yeah true, but ... seems that this was not done for form_for.
    Can you guys confirm this? if it was not done for form_for can you provide a patch for it using the same approach?.
    Thanks.

    February 5th, 2011 @ 12:22 AM

  7. 2kan
    2kan

    Santiago, since form_for works through form_tag we need just to write something like:

    form_for(@something, :html => { :authenticity_token => 'some_token_of_false' }) do |f|
    

    So right now this ticket is duplicate to functionality committed in #2988.

    February 5th, 2011 @ 03:14 AM

  8. Santiago Pastorino
    Santiago Pastorino

    2kan right, but we don't have tests and docs for form_for though.

    February 5th, 2011 @ 03:49 AM

  9. 2kan
    2kan

    Added test for for_for and new authenticity_token option. Added docs. Added section about it to form helpers guide. All in one single patch.

    February 5th, 2011 @ 03:41 PM

  10. Repository
    Repository
    • State changed from open to committed

    (from [b9309b47cda12db34ac3427fbafff2dca0314ed7]) Added tests for form_for and an authenticity_token option. Added docs for for_for and authenticity_token option. Added section to form helpers guide about forms for external resources and new authenticity_token option for form_tag and form_for helpers.

    [#6228 state:committed]

    Signed-off-by: Santiago Pastorino santiago@wyeworks.com
    https://github.com/rails/rails/commit/b9309b47cda12db34ac3427fbafff...

    February 5th, 2011 @ 09:02 PM

  11. Dan Pickett
    Dan Pickett

    I dig the change, but I think putting the authenticity_token arg in the html option hash is unintuitive. I've attached a patch that puts the function in parity with the remote option.

    February 6th, 2011 @ 04:27 PM

  12. Dan Pickett
    Dan Pickett
    • State changed from committed to open

    [state:open]

    February 6th, 2011 @ 06:17 PM

  13. Santiago Pastorino
    Santiago Pastorino

    Yeah agree pushing the change

    February 6th, 2011 @ 09:05 PM

  14. Repository
    Repository
    • State changed from open to committed

    (from [3026843dc1ff42a632ebe989e1f6dfadb0cd10a5]) put authenticity_token option in parity w/ remote

    [#6228 state:committed]

    Signed-off-by: Santiago Pastorino santiago@wyeworks.com
    https://github.com/rails/rails/commit/3026843dc1ff42a632ebe989e1f6d...

    February 6th, 2011 @ 09:05 PM

  15. 2kan
    2kan
    • State changed from committed to open

    [state:open]

    Updated form helpers guide for new place of authenticity_token option in for_for helper.

    February 7th, 2011 @ 11:39 AM

  16. Santiago Pastorino
    Santiago Pastorino
    • State changed from open to resolved

    Pushed

    February 7th, 2011 @ 12:51 PM