Skip to content

Commit e32847f

Browse files
committed
fixed CSRF overprotection & incorrect store use of sessions_controller
1 parent addb26d commit e32847f

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

app/controllers/users/sessions_controller.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
class Users::SessionsController < Devise::SessionsController
22
include Devise::Controllers::Rememberable
33

4-
protect_from_forgery except: [:create]
4+
protect_from_forgery with: :exception, except: [:create, :destroy], store: :cookie
55

66
mattr_accessor :first_factor, default: [], instance_writer: false, instance_reader: false
77

0 commit comments

Comments
 (0)