forked from weavejester/ring-anti-forgery
-
Notifications
You must be signed in to change notification settings - Fork 26
Closed
Description
On the readme there is a caveat about using ring-anti-forgery with web services. But it can work with those just fine and would even work out of the box if the default access-denied response included the token on the header - if the client just send the token back with its request.
Could this header be in the access-denied response by default? Or can you think about reasons not to do it?
Thanks.
Metadata
Metadata
Assignees
Labels
No labels