Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Generate form_authenticity_token correctly when using CookieStore and Secret present

#957

Currently if you're using the CookieStore, and accidentally call protect_from_forgery with a :secret param, then the form_authenticity_token won't be generated correctly, and will result in InvalidAuthenticityToken errors being raised

I had this scenerio today after I'd switched back to the CookieStore from another store, and had forgotten to remove the secret.

The attached patch (with tests) makes the form_authenticity_token check to see if the CookieStore is being used rather than simply assuming it's not if :secret is set.

I'm happy to take any feedback on how to improve the tests - or any performance impact the new conditions might have. As well as the attached tests I've run and tested my app with this patch applied.

Reported by Tim Haines · September 2nd, 2008 @ 01:26 PM

State: invalid
Milestone: 2.x
Assigned to: Michael Koziarski Michael Koziarski
Importance: none

Activity

  1. Tim Haines
    Tim Haines

    This patch (or one like it) also has the side benefit of being able to simplify the generated code for ActionController. The :secret could be uncommented by default, and the comment on the line above could be removed.

    September 2nd, 2008 @ 09:18 PM

  2. Michael Koziarski
    Michael Koziarski

    You don't seem to actually make any requests in the tests? Did the old behaviour raise errors before requesting anything?

    September 3rd, 2008 @ 08:40 AM

  3. Michael Koziarski
    Michael Koziarski
    • Assigned user set to Michael Koziarski

    September 3rd, 2008 @ 08:41 AM

  4. Tim Haines
    Tim Haines

    Requests are made via the module that's included -> include RequestForgeryProtectionTests This is the same pattern that is used for the other request_forgery_pattern_tests.

    Yes - if you add my tests without changing the source file, some of the tests will fail. The tests pass after you change the source file.

    September 3rd, 2008 @ 09:25 AM

  5. Tim Haines
    Tim Haines
    • Title changed from Ignore secret when Cookie Store is used to Generate form_authenticity_token correctly when using CookieStore and Secret present

    September 3rd, 2008 @ 09:37 AM

  6. Frederick Cheung
    Frederick Cheung
    • State changed from new to invalid

    No longer relevant since form_authenticity_token was reimplemented along a completely different method in (9fdb15e60f4d4e37916e5354c50d559773bbe014)[http://github.com/rails/rails/co...]

    December 12th, 2008 @ 02:18 PM

  7. bingbing