Class: SuperGood::CSRFProtection

Inherits:
Object
  • Object
show all
Defined in:
lib/super_good/csrf_protection.rb,
lib/super_good/csrf_protection/version.rb

Defined Under Namespace

Classes: Error

Constant Summary collapse

SAFE_METHODS =
%w[GET HEAD OPTIONS].freeze
SAFE_SEC_FETCH_SITE_VALUES =
%w[same-origin none].freeze
VERSION =
"0.2.0"

Instance Method Summary collapse

Constructor Details

#initialize(app, raise_error: false) ⇒ CSRFProtection

Returns a new instance of CSRFProtection.



12
13
14
15
# File 'lib/super_good/csrf_protection.rb', line 12

def initialize(app, raise_error: false)
  @app = app
  @raise_error = raise_error
end

Instance Method Details

#call(env) ⇒ Object



17
18
19
20
21
22
23
24
25
# File 'lib/super_good/csrf_protection.rb', line 17

def call(env)
  return @app.call(env) unless unsafe_request?(env) && cross_origin?(env)

  if @raise_error
    raise(Error, "Cross-origin request denied")
  else
    [403, {"Content-Type" => "text/plain"}, ["Forbidden"]]
  end
end