Class: SuperGood::CSRFProtection
- Inherits:
-
Object
- Object
- SuperGood::CSRFProtection
- Defined in:
- lib/super_good/csrf_protection.rb,
lib/super_good/csrf_protection/version.rb
Defined Under Namespace
Classes: Error
Constant Summary collapse
- SAFE_METHODS =
%w[GET HEAD OPTIONS].freeze
- SAFE_SEC_FETCH_SITE_VALUES =
%w[same-origin none].freeze
- VERSION =
"0.2.0"
Instance Method Summary collapse
- #call(env) ⇒ Object
-
#initialize(app, raise_error: false) ⇒ CSRFProtection
constructor
A new instance of CSRFProtection.
Constructor Details
#initialize(app, raise_error: false) ⇒ CSRFProtection
Returns a new instance of CSRFProtection.
12 13 14 15 |
# File 'lib/super_good/csrf_protection.rb', line 12 def initialize(app, raise_error: false) @app = app @raise_error = raise_error end |
Instance Method Details
#call(env) ⇒ Object
17 18 19 20 21 22 23 24 25 |
# File 'lib/super_good/csrf_protection.rb', line 17 def call(env) return @app.call(env) unless unsafe_request?(env) && cross_origin?(env) if @raise_error raise(Error, "Cross-origin request denied") else [403, {"Content-Type" => "text/plain"}, ["Forbidden"]] end end |