mirror of
https://github.com/basecamp/once-campfire.git
synced 2026-10-10 00:30:13 +09:00
Use header-only forgery protection and cache complete responses
This commit is contained in:
@@ -7,6 +7,7 @@
|
||||
# can read the public login page. Require a valid Campfire session before an
|
||||
# anonymous caller can allocate a Blob or persist bytes to disk.
|
||||
Rails.application.config.to_prepare do
|
||||
ActiveStorage::BaseController.forgery_protection_verification_strategy = :header_only
|
||||
ActiveStorage::DirectUploadsController.include ActiveStorageAuthentication
|
||||
ActiveStorage::DirectUploadsController.before_action :require_active_storage_authentication
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
Rails.application.config.session_store :cookie_store,
|
||||
key: "_campfire_session",
|
||||
# Persist session cookie as permament so re-opened browser windows maintain a CSRF token
|
||||
# Preserve the existing installation's persistent browser-session cookie.
|
||||
expire_after: 20.years
|
||||
|
||||
Reference in New Issue
Block a user