Skip to content

Commit

Permalink
R2-3046: Conflict between CSRF token and IDP auth
Browse files Browse the repository at this point in the history
  • Loading branch information
jtoliver-quoin committed Oct 3, 2024
1 parent 6c3c602 commit f0c608e
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion app/auth/idp_token_strategy.rb
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ def valid?

# This is an override for warden to skip storing session in a cookie
def store?
false
true
end

def authenticate!
Expand Down
2 changes: 1 addition & 1 deletion app/controllers/application_api_controller.rb
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ class ApplicationApiController < ActionController::API
before_action :check_config_update_lock!
before_action :set_csrf_cookie, unless: -> { request_from_basic_auth? }

protect_from_forgery with: :exception, prepend: true, if: -> { use_csrf_protection? }
protect_from_forgery with: :exception, if: -> { use_csrf_protection? }

class << self
attr_accessor :model_class
Expand Down

0 comments on commit f0c608e

Please sign in to comment.