Tell me about your PUT requests to Rails endpoints from client-side frameworks (no jQuery UJS) & how you dealt with CSRF token.
-
-
Replying to @olivierlacan
I completely sailed passed the whole CSRF is now masked and always appears different in Rails 4.2. Rude awakening.
1 reply 0 retweets 0 likes -
Replying to @olivierlacan
Also please tell me protect_from_forgery with: :exception is default in Rails 5. Lost hours of my life yet again to silent errors.
2 replies 0 retweets 0 likes -
-
Replying to @sgrif
It’s not the default in Rails 4.2 so I’m not sure what you mean.
3 replies 0 retweets 0 likes
Replying to @olivierlacan
New apps have been generated to use `:exception` for as long as it's been possible to do so (4.0) https://github.com/rails/rails/commit/245941101b1ea00a9b1af613c20b0ee994a43946 …
5:18 PM - 16 Aug 2016
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.