mirror of
https://github.com/basecamp/once-campfire.git
synced 2026-10-09 16:20:09 +09:00
Use header-only forgery protection and cache complete responses
This commit is contained in:
@@ -14,8 +14,7 @@ class MessagesController < ApplicationController
|
||||
if @messages.any?
|
||||
body = render_to_string(:index)
|
||||
# Creator, body and boost edits can change HTML without touching messages.
|
||||
# Masked CSRF tokens remain fresh while the presentation validator stays stable.
|
||||
fresh_when etag: Digest::SHA256.hexdigest(csrf_neutral_body(body, "")), template: false
|
||||
fresh_when etag: Digest::SHA256.hexdigest(body), template: false
|
||||
unless performed?
|
||||
response.content_type = "text/html"
|
||||
self.response_body = body
|
||||
|
||||
Reference in New Issue
Block a user