Class: Rack::Protection::RemoteReferrer
- Defined in:
- lib/rack/protection/remote_referrer.rb
Overview
- Prevented attack
-
CSRF
- Supported browsers
-
all
- More infos
Does not accept unsafe HTTP requests if the Referer [sic] header is set to a different host.
Constant Summary
Constants inherited from Base
Instance Attribute Summary
Attributes inherited from Base
Instance Method Summary collapse
Methods inherited from Base
#call, #default_options, default_options, default_reaction, #deny, #drop_session, #encrypt, #html?, #initialize, #instrument, #origin, #random_string, #react, #referrer, #report, #safe?, #secure_compare, #session, #session?, #warn
Constructor Details
This class inherits a constructor from Rack::Protection::Base
Instance Method Details
#accepts?(env) ⇒ Boolean
17 18 19 |
# File 'lib/rack/protection/remote_referrer.rb', line 17 def accepts?(env) safe?(env) or referrer(env) == Request.new(env).host end |