Skip to content

ring-anti-forgery and web services #2

@mynomoto

Description

@mynomoto

On the readme there is a caveat about using ring-anti-forgery with web services. But it can work with those just fine and would even work out of the box if the default access-denied response included the token on the header - if the client just send the token back with its request.

Could this header be in the access-denied response by default? Or can you think about reasons not to do it?

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions