Update CSRF chain to prepend checks and resolve comments from PR

Signed-off-by: Sebastian Serth <Sebastian.Serth@student.hpi.de>
This commit is contained in:
Sebastian Serth
2018-09-24 16:27:13 +02:00
parent 4809f7bc03
commit a77a006e8d
3 changed files with 3 additions and 6 deletions

View File

@ -6,7 +6,7 @@ class ApplicationController < ActionController::Base
after_action :verify_authorized, except: [:help, :welcome]
before_action :set_locale, :allow_iframe_requests
protect_from_forgery(with: :exception)
protect_from_forgery(with: :exception, prepend: true)
rescue_from Pundit::NotAuthorizedError, with: :render_not_authorized
def current_user