instance method
verified_request?
Ruby on Rails 7.2.3
Since v2.2.3 PrivateSignature
verified_request?()
Returns true or false if a request is verified. Checks:
-
Is it a GET or HEAD request? GETs should be safe and idempotent
-
Does the form_authenticity_token match the given token value from the params?
-
Does the
X-CSRF-Tokenheader match the form_authenticity_token?
Source
# File actionpack/lib/action_controller/metal/request_forgery_protection.rb, line 463
def verified_request? # :doc:
!protect_against_forgery? || request.get? || request.head? ||
(valid_request_origin? && any_authenticity_token_valid?)
end
Defined in actionpack/lib/action_controller/metal/request_forgery_protection.rb line 463
· View on GitHub
· Improve this page
· Find usages on GitHub
Defined in ActionController::RequestForgeryProtection