Class: Cuba::Safe::CSRF::Helper
- Inherits:
-
Object
- Object
- Cuba::Safe::CSRF::Helper
- Defined in:
- lib/cuba/safe/csrf.rb
Instance Attribute Summary collapse
-
#req ⇒ Object
readonly
Returns the value of attribute req.
Instance Method Summary collapse
- #form_tag ⇒ Object
-
#initialize(req) ⇒ Helper
constructor
A new instance of Helper.
- #meta_tag ⇒ Object
- #reset! ⇒ Object
- #safe? ⇒ Boolean
- #session ⇒ Object
- #token ⇒ Object
- #unsafe? ⇒ Boolean
Constructor Details
#initialize(req) ⇒ Helper
Returns a new instance of Helper.
11 12 13 |
# File 'lib/cuba/safe/csrf.rb', line 11 def initialize(req) @req = req end |
Instance Attribute Details
#req ⇒ Object (readonly)
Returns the value of attribute req.
9 10 11 |
# File 'lib/cuba/safe/csrf.rb', line 9 def req @req end |
Instance Method Details
#form_tag ⇒ Object
33 34 35 |
# File 'lib/cuba/safe/csrf.rb', line 33 def form_tag return %Q(<input type="hidden" name="csrf_token" value="#{ token }">) end |
#meta_tag ⇒ Object
37 38 39 |
# File 'lib/cuba/safe/csrf.rb', line 37 def return %Q(<meta name="csrf_token" content="#{ token }">) end |
#reset! ⇒ Object
19 20 21 |
# File 'lib/cuba/safe/csrf.rb', line 19 def reset! session.delete(:csrf_token) end |
#safe? ⇒ Boolean
23 24 25 26 27 |
# File 'lib/cuba/safe/csrf.rb', line 23 def safe? return req.get? || req.head? || req.params["csrf_token"] == token || req.env["HTTP_X_CSRF_TOKEN"] == token end |
#session ⇒ Object
41 42 43 |
# File 'lib/cuba/safe/csrf.rb', line 41 def session return req.env["rack.session"] end |
#token ⇒ Object
15 16 17 |
# File 'lib/cuba/safe/csrf.rb', line 15 def token session[:csrf_token] ||= SecureRandom.base64(32) end |
#unsafe? ⇒ Boolean
29 30 31 |
# File 'lib/cuba/safe/csrf.rb', line 29 def unsafe? return !safe? end |