instance method verified_request?

Ruby on Rails edge

Private — implementation detail, not part of the public API

Available in: v2.2.3 v2.3.18 v3.0.20 v3.1.12 v3.2.22.5 v4.0.13 v4.1.16 v5.2.8.1 v6.0.6.1 v6.1.7.10 v7.0.10 v7.1.6 v7.2.3.2 v8.0.5.1 v8.1.3.1 edge

Signature

verified_request?()

Returns true or false if a request is verified. The verification method depends on the configured forgery_protection_verification_strategy:

  • :header_only - Uses Sec-Fetch-Site header only (default)

  • :header_or_legacy_token - Uses Sec-Fetch-Site header with fallback to token

For all strategies, GET, HEAD, and QUERY requests are allowed without verification. HTML forms cannot issue QUERY requests, and cross-origin QUERY requests always require a CORS preflight, so they cannot be forged through a victim’s browser. A request tunneled through a form POST with _method=query does not share that protection, so it is verified like any other POST.

Source
# File actionpack/lib/action_controller/metal/request_forgery_protection.rb, line 615
      def verified_request? # :doc:
        request.get? || request.head? || verified_query_request? || !protect_against_forgery? ||
          (valid_request_origin? && verified_request_for_forgery_protection?)
      end

Defined in actionpack/lib/action_controller/metal/request_forgery_protection.rb line 615 · View on GitHub · Improve this page · Find usages on GitHub

Defined in ActionController::RequestForgeryProtection

Type at least 2 characters to search.

Use the arrow keys to navigate results, Enter to open one, Escape to close.

Keyboard shortcuts

/
Focus search
⌘K / Ctrl-K
Command palette
?
This help
Esc
Close