Use header-only forgery protection and cache complete responses

This commit is contained in:
GPT on behalf of DHH
2026-10-08 09:05:10 +02:00
parent 008ea1ab2a
commit 0f5d0b2b6e
12 changed files with 169 additions and 54 deletions
@@ -7,6 +7,7 @@
# can read the public login page. Require a valid Campfire session before an
# anonymous caller can allocate a Blob or persist bytes to disk.
Rails.application.config.to_prepare do
ActiveStorage::BaseController.forgery_protection_verification_strategy = :header_only
ActiveStorage::DirectUploadsController.include ActiveStorageAuthentication
ActiveStorage::DirectUploadsController.before_action :require_active_storage_authentication
+1 -1
View File
@@ -1,4 +1,4 @@
Rails.application.config.session_store :cookie_store,
key: "_campfire_session",
# Persist session cookie as permament so re-opened browser windows maintain a CSRF token
# Preserve the existing installation's persistent browser-session cookie.
expire_after: 20.years