class ActionController::RequestForgeryProtection::ProtectionMethods::NullSession
Public class methods
Source code GitHub
# File actionpack/lib/action_controller/metal/request_forgery_protection.rb, line 260
def initialize(controller)
@controller = controller
end
Public instance methods
This is the method that defines the application behavior when a request is found to be unverified.
Source code GitHub
# File actionpack/lib/action_controller/metal/request_forgery_protection.rb, line 266
def handle_unverified_request
request = @controller.request
request.session = NullSessionHash.new(request)
request.flash = nil
request.session_options = { skip: true }
request.cookie_jar = NullCookieJar.build(request, {})
end