3 ms·
Can somebody post the tldr?
by TwoBit 15y ago
Can somebody post the tldr?
- jerfelix 15y agotldr: There were some recent changes in Rails in the portion of the code that handles CSRF protection, specifically around handling AJAX. Users' sessions were getting dropped and it was costing him money.
- stdbrouw 15y agoIt's just a fun read, the info about CSRF in Rails will, for most people, be inconsequential. Thus, the tldr is: bookmark this for when you have ten minutes of spare time. :)
- mechanical_fish 15y agoFrom the first sentence: This post will not help you sell more software. If you’re not fascinated by the inner workings of complex systems, go do something more important. If you are, grab some popcorn, because this is the best bug I’ve seen in years. There's no real point in summarizing further. It's like asking someone to summarize Hamlet for you [1] because you'd rather not sit through all that acting and dialogue. The point of this story is that it's a big complex meandering story that ultimately culminates in an anticlimactic technical issue. You know, kind of like most of my job. --- [1] "Almost all the peers in Denmark die violently one by one."
- scott_s 15y ago"Cesarean section results in regicide, 30 years later." "Rebellious teenagers escape parental control."
- TwoBit 15y agoJust because it's interesting to you or the author doesn't mean it's interesting to everybody else. I've seen many posts by programmers who think they discovered something great and it turns out to be something others have seen 100 times.
- rhizome 15y agoRails 2.3.11 turned CSRF violations into silent retries, which can be a problem if you track session IDs closely.
- anthonyb 15y agotl;dr is a blight upon society
- DanBC 15y agoNot sure why you're getting downvoted. People should be able to read well-written interesting articles.