change: use skip_forgery_protection instead of manually set skip_before_action#1212
Merged
excid3 merged 2 commits intopay-rails:mainfrom Dec 23, 2025
Merged
Conversation
808c165 to
fb805b3
Compare
Collaborator
|
I just realized, we should probably just inherit from I will refactor this in another PR. |
Contributor
Author
|
What's interesting now is that I'm getting it's weird because the method is present in the stable and edge API. I'm trying to understad what's going on |
Contributor
Author
|
ah, just realized you already changed the inheritance in the new version, sorry! I think |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Summary:
in Rails edge, the CSRF verification has changed from authenticity token to header-based (Sec-Fetch-Site).
This breaks
skip_before_actionasverify_authenticity_tokenwas removed (here and here)A simple fix is to use the helper skip_forgery_protection as it is a wrapper for
skip_before_action :verify_authenticity_tokenalready and it works for both versions of the codeRelated Issue:
Description:
Testing:
Screenshots (if applicable):
Checklist: