instance method verify_request_for_forgery_protection

Ruby on Rails edge

Since edge Private — implementation detail, not part of the public API

Signature

verify_request_for_forgery_protection()

The actual before_action that is used to verify the request to protect from forgery. Don’t override this directly. Provide your own forgery protection strategy instead. If you override, you’ll disable same-origin <script> verification.

Lean on the protect_from_forgery declaration to mark which actions are due for same-origin request verification. If protect_from_forgery is enabled on an action, this before_action flags its after_action to verify that JavaScript responses are for XHR requests, ensuring they follow the browser’s same-origin policy.

Source
# File actionpack/lib/action_controller/metal/request_forgery_protection.rb, line 516
      def verify_request_for_forgery_protection # :doc:
        if @_verify_authenticity_token_ran
          mark_for_same_origin_verification!

          if !verified_request?
            instrument_unverified_request

            handle_unverified_request
          end
        else
          ActiveSupport.deprecator.warn(<<~MSG.squish)
            `verify_authenticity_token` is deprecated and will be removed in a future Rails version.
            To skip forgery protection, use `skip_forgery_protection` instead of skipping `verify_authenticity_token`
            as this won't have any effect in a future Rails version.
          MSG
        end
      end

Defined in actionpack/lib/action_controller/metal/request_forgery_protection.rb line 516 · View on GitHub · Improve this page · Find usages on GitHub

Defined in ActionController::RequestForgeryProtection

Type at least 2 characters to search.

Use the arrow keys to navigate results, Enter to open one, Escape to close.

Keyboard shortcuts

/
Focus search
⌘K / Ctrl-K
Command palette
?
This help
Esc
Close