Permalink
Browse files

Document how to disable forgery protection for tests. Useful note for…

… those upgrading from 1.x. Closes #10440 [Trevor Turk]

git-svn-id: http://svn-commit.rubyonrails.org/rails/trunk@8350 5ecf4fe2-1ee6-0310-87b1-e25e094e27de
  • Loading branch information...
1 parent a93fea8 commit 380ddd5310753fdf3082198e719642d44c68e69f @jeremy jeremy committed Dec 10, 2007
Showing with 7 additions and 1 deletion.
  1. +7 −1 actionpack/lib/action_controller/request_forgery_protection.rb
@@ -54,6 +54,12 @@ module ClassMethods
# skip_before_filter :verify_authenticity_token
# end
#
+ # If you are upgrading from Rails 1.x, disable forgery protection to
+ # simplify your tests. Add this to config/environments/test.rb:
+ #
+ # # Disable request forgery protection in test environment
+ # config.action_controller.allow_forgery_protection = false
+ #
# Valid Options:
#
# * <tt>:only/:except</tt> - passed to the before_filter call. Set which actions are verified.
@@ -123,4 +129,4 @@ def protect_against_forgery?
allow_forgery_protection && request_forgery_protection_token
end
end
-end
+end

0 comments on commit 380ddd5

Please sign in to comment.