By restricting role changes to POST requests, which they should be anyway, we get all the rails CSRF protection for free. |
||
---|---|---|
.. | ||
fixtures | ||
functional | ||
integration | ||
performance | ||
unit | ||
test_helper.rb |
By restricting role changes to POST requests, which they should be anyway, we get all the rails CSRF protection for free. |
||
---|---|---|
.. | ||
fixtures | ||
functional | ||
integration | ||
performance | ||
unit | ||
test_helper.rb |