Prevent CSRF bypass with login form
This commit is contained in:
parent
a17bd24f82
commit
1f136a84a6
5 changed files with 33 additions and 5 deletions
|
@ -276,7 +276,7 @@ class UsersController < ApplicationController
|
|||
|
||||
session[:referer] = safe_referer(params[:referer]) if params[:referer]
|
||||
|
||||
if params[:username].present? && params[:password].present?
|
||||
if request.post?
|
||||
session[:remember_me] ||= params[:remember_me]
|
||||
password_authentication(params[:username], params[:password])
|
||||
end
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue