3 ms·
This looks wide open to csrf attacks. Another site can post a form on behalf of a user automatically, and the cookies for job poacher will be sent. Meaning tha
by scriby 15y ago
This looks wide open to csrf attacks.
Another site can post a form on behalf of a user automatically, and the cookies for job poacher will be sent. Meaning that a malicious site can take actions on behalf of a logged in user.
Perhaps their solution is more complicated than they let on, but I doubt it given it's "20 lines of code".
- cheald 15y agoRails has CSRF protections baked in; unless you explicitly turn it off, non-GET requests require a CSRF token associated with the user session to complete successfully.
- scriby 15y agoThat makes sense. I've been doing node js too long where you have to do this stuff by hand :0
- zaroth 15y agothat has nothing to do with using a password or not to authenticate. anti-forgery tokens are the answer to csrf.
- joevandyk 15y agoThis is why you check for tokens in the form that correspond to the current user's session. Rails does this for you automatically.