Use header-only forgery protection and cache complete responses

This commit is contained in:
GPT on behalf of DHH
2026-10-08 09:05:10 +02:00
parent 008ea1ab2a
commit 0f5d0b2b6e
12 changed files with 169 additions and 54 deletions
+1 -2
View File
@@ -14,8 +14,7 @@ class MessagesController < ApplicationController
if @messages.any?
body = render_to_string(:index)
# Creator, body and boost edits can change HTML without touching messages.
# Masked CSRF tokens remain fresh while the presentation validator stays stable.
fresh_when etag: Digest::SHA256.hexdigest(csrf_neutral_body(body, "")), template: false
fresh_when etag: Digest::SHA256.hexdigest(body), template: false
unless performed?
response.content_type = "text/html"
self.response_body = body