instance method
verified_request?
Ruby on Rails 2.3.18
Since v2.2.3Signature
verified_request?()
Returns true or false if a request is verified. Checks:
-
is the format restricted? By default, only HTML requests are checked.
-
is it a GET request? Gets should be safe and idempotent
-
Does the form_authenticity_token match the given token value from the params?
Source
# File actionpack/lib/action_controller/request_forgery_protection.rb, line 91
def verified_request?
!protect_against_forgery? ||
request.get? ||
form_authenticity_token == form_authenticity_param ||
form_authenticity_token == request.headers['X-CSRF-Token']
end
Defined in actionpack/lib/action_controller/request_forgery_protection.rb line 91
· View on GitHub
· Improve this page
· Find usages on GitHub
Defined in ActionController::RequestForgeryProtection