Skip to content

Comment on Security patch releases to Rails 2.3.x, 3.0.xparent

Comments

I'm just messing with you both.

Resetting sessions on CSRF failures is going to suck for us.

Is there any reason to reset the session on a CSRF failure vs. just failing the request? Seems like you could have fun DOSing people from their sessions on other sites with that default behavior.

That's right. Of course, without knowing more details about the vulnerability, it's hard to say whether there's a benefit to ending the session.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.