By restricting role changes to POST requests, which they should be anyway, we get all the rails CSRF protection for free. |
||
---|---|---|
.. | ||
client_application_test.rb | ||
oauth_test.rb | ||
short_link_test.rb | ||
user_blocks_test.rb | ||
user_creation_test.rb | ||
user_diaries_test.rb | ||
user_login_test.rb | ||
user_roles_test.rb | ||
user_terms_seen_test.rb |