instance method
verified_via_header_only?
Ruby on Rails edge
Since edge Private — implementation detail, not part of the public APISignature
verified_via_header_only?()
No documentation comment.
Source
# File actionpack/lib/action_controller/metal/request_forgery_protection.rb, line 642
def verified_via_header_only?
case sec_fetch_site_value
when "same-origin", "same-site"
true
when "cross-site"
origin_trusted?
when nil
!request.ssl? && !ActionDispatch::Http::URL.secure_protocol
else
false
end
end
Defined in actionpack/lib/action_controller/metal/request_forgery_protection.rb line 642
· View on GitHub
· Improve this page
· Find usages on GitHub
Defined in ActionController::RequestForgeryProtection