Pawel
Not a member
Pawel's latest activity
Tuesday, March 15 2011
-
Pawel commented at 12:53 PMI was testing this only on 3.0.5.
From reading the edge source code it appears to be fixed, so the bug could be closed now.
Wednesday, March 09 2011
-
Pawel created the ticket at 9:15 PMIn the classic Group <-> Membership <-> User scenario:
class Group has_many :memberships has_many :users, :through => :memberships end class Membership ...
Tuesday, March 24 2009
-
Pawel commented at 11:04 AMIMHO reset_session should be simplified to three steps: 1. Clear the session variables. 2. Remove the cookie with session_id. 3. There is no step three ;-)
When...
Wednesday, March 18 2009
-
Pawel commented at 4:12 PMA workaround to allow your users to log in. Read the comment or don't use it.
class ApplicationController # This will destroy session fixation protection ... -
- Tag set to 2.3.2, activerecord-store, cookie-store, reset_session, session
- Title changed from session support broken to reset_session broken
Described problem affects also ActiveRecord session store, but also in development mode.
def login reset_session session[:user_id] = 5 redirect_to :action => 'l...
-
- Tag changed from 2.3, rails, request.session:id, session.session_id to 2.3, rails, request.session_options:id, session.session_id
This is because of session lazy loading.
You can work around this by loading the session first and then read its id.
def something session[:foo] user_c...
Monday, March 09 2009
-
Pawel created the ticket at 11:10 AMThis is the current implementation of form_authenticity_token:
def form_authenticity_token session[:_csrf_token] ||= ActiveSupport::SecureRandom.base64(32...
Sunday, March 08 2009
-
Pawel created the ticket at 11:34 PMFollowing code demonstrates race condition in session handling:
def action_that_should_be_called_only_once_per_session my_custom_lock_for_current_session ...