Please forward to RoR crowd ( my news-server doesn't carry, and I'm

  • Thread starter Antryg Bogus Address
  • Start date
P

Paul Stickney

Article on Cross Site Request forgery, saying that only a solution internal-to-the-server can break the technique, and only if
it's so pervasive that the attack itself becomes worthless.

I haven't been keeping up on RoR, but different frameworks such as
Seaside (Smalltalk) and Lift/Liftweb (Scala) avoid the issue by using
mapped tokens. RoR might have extensions/plugins that offer the same
functionality. I am unfamiliar how TG, Wicket or other [Ruby] web
frameworks avoid/handle the problem. In a sense, this is just an
extension of the "destructive GET requests" that RoR worked to remove
~1.2 (IIRC).

That being said, wrong ML :)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,769
Messages
2,569,580
Members
45,054
Latest member
TrimKetoBoost

Latest Threads

Top