Commit Graph

13 Commits

Author SHA1 Message Date
GitLab Bot 9a940dabf0 Add latest changes from gitlab-org/gitlab@master 2023-12-07 15:12:19 +00:00
GitLab Bot 277496b843 Add latest changes from gitlab-org/gitlab@master 2023-10-26 21:10:31 +00:00
GitLab Bot 272c39ac05 Add latest changes from gitlab-org/gitlab@master 2023-09-27 00:10:14 +00:00
GitLab Bot 59f37a9943 Add latest changes from gitlab-org/gitlab@master 2022-11-07 18:08:08 +00:00
GitLab Bot c014b6b4e5 Add latest changes from gitlab-org/gitlab@master 2022-09-14 15:12:56 +00:00
GitLab Bot 577bb49691 Add latest changes from gitlab-org/gitlab@master 2021-02-10 18:09:02 +00:00
GitLab Bot 4fc6f62c16 Add latest changes from gitlab-org/gitlab@master 2020-11-25 00:09:24 +00:00
gfyoung c858f70d07 Enable frozen string for lib/gitlab/*.rb 2018-10-22 07:00:50 +00:00
blackst0ne 6fef87f17f [Rails5] Force the `protect_from_forgery` callback run first
Since Rails 5.0 the `protect_from_forgery` callback doesn't run first by
default anymore. [1]

Instead it gets inserted into callbacks chain where callbacks get
called in order.

This commit forces the callback to run first.

[1]: 3979403781
2018-06-21 21:44:31 +11:00
Douwe Maan d020eabf29 Add log messages to clarify log messages about API CSRF token verification failure 2017-07-28 15:39:39 +02:00
Douwe Maan dcf4a2e83c Rescue only from ActionController::InvalidAuthenticityToken 2017-07-26 11:25:10 +02:00
blackst0ne cc3a82bc8b Add `rescue false`. 2017-07-26 11:05:44 +02:00
blackst0ne 8ce8b21f67 Refactor CSRF protection 2017-07-26 11:05:44 +02:00