This project is archived and is in readonly mode.
Generate form_authenticity_token correctly when using CookieStore and Secret present
-
Tim Haines
This patch (or one like it) also has the side benefit of being able to simplify the generated code for ActionController. The :secret could be uncommented by default, and the comment on the line above could be removed.
-
Michael Koziarski
You don't seem to actually make any requests in the tests? Did the old behaviour raise errors before requesting anything?
-
Michael Koziarski
- Assigned user set to Michael Koziarski
-
Tim Haines
Requests are made via the module that's included -> include RequestForgeryProtectionTests This is the same pattern that is used for the other request_forgery_pattern_tests.
Yes - if you add my tests without changing the source file, some of the tests will fail. The tests pass after you change the source file.
-
Tim Haines
- Title changed from Ignore secret when Cookie Store is used to Generate form_authenticity_token correctly when using CookieStore and Secret present
-
Frederick Cheung
- State changed from new to invalid
No longer relevant since form_authenticity_token was reimplemented along a completely different method in (9fdb15e60f4d4e37916e5354c50d559773bbe014)[http://github.com/rails/rails/co...]
