From de4563ddb1a2ef95e58de2eaae4b102ac8275de4 Mon Sep 17 00:00:00 2001 From: Rob Smith Date: Thu, 15 Sep 2016 20:33:44 -0700 Subject: [PATCH] Remote forgery protection for json requests to the api/v1 endpoints Due to my testing, I incorrectly removed the forgery protection skip action from the controllers in the api. This fixes that and allows jsonp calls to work correctly --- app/controllers/api/v1/conferences_controller.rb | 3 +++ app/controllers/api/v1/events_controller.rb | 3 +++ app/controllers/api/v1/rooms_controller.rb | 3 +++ app/controllers/api/v1/speakers_controller.rb | 3 +++ app/controllers/api/v1/tracks_controller.rb | 3 +++ 5 files changed, 15 insertions(+) diff --git a/app/controllers/api/v1/conferences_controller.rb b/app/controllers/api/v1/conferences_controller.rb index 1fddf1b4..60578587 100644 --- a/app/controllers/api/v1/conferences_controller.rb +++ b/app/controllers/api/v1/conferences_controller.rb @@ -4,6 +4,9 @@ module Api load_resource find_by: :short_title respond_to :json + # Disable forgery protection for any json requests. This is required for jsonp support + skip_before_action :verify_authenticity_token + def index render json: @conferences, serializer: ConferencesArraySerializer, callback: params['callback'] end diff --git a/app/controllers/api/v1/events_controller.rb b/app/controllers/api/v1/events_controller.rb index 20578dd8..1cb01ad9 100644 --- a/app/controllers/api/v1/events_controller.rb +++ b/app/controllers/api/v1/events_controller.rb @@ -4,6 +4,9 @@ module Api load_resource :conference, find_by: :short_title respond_to :json + # Disable forgery protection for any json requests. This is required for jsonp support + skip_before_action :verify_authenticity_token + def index events = Event.includes(:track, :event_type, event_users: :user) diff --git a/app/controllers/api/v1/rooms_controller.rb b/app/controllers/api/v1/rooms_controller.rb index 3046d51f..ecc959fa 100644 --- a/app/controllers/api/v1/rooms_controller.rb +++ b/app/controllers/api/v1/rooms_controller.rb @@ -4,6 +4,9 @@ module Api load_resource :conference, find_by: :short_title respond_to :json + # Disable forgery protection for any json requests. This is required for jsonp support + skip_before_action :verify_authenticity_token + def index if @conference respond_with @conference.venue ? @conference.venue.rooms : Room.none, callback: params[:callback] diff --git a/app/controllers/api/v1/speakers_controller.rb b/app/controllers/api/v1/speakers_controller.rb index cbdb4379..2706d2e9 100644 --- a/app/controllers/api/v1/speakers_controller.rb +++ b/app/controllers/api/v1/speakers_controller.rb @@ -4,6 +4,9 @@ module Api load_resource :conference, find_by: :short_title respond_to :json + # Disable forgery protection for any json requests. This is required for jsonp support + skip_before_action :verify_authenticity_token + def index if @conference users = User.joins(event_users: { event: { program: :conference} }) diff --git a/app/controllers/api/v1/tracks_controller.rb b/app/controllers/api/v1/tracks_controller.rb index a2033867..48a9450f 100644 --- a/app/controllers/api/v1/tracks_controller.rb +++ b/app/controllers/api/v1/tracks_controller.rb @@ -4,6 +4,9 @@ module Api load_resource :conference, find_by: :short_title respond_to :json + # Disable forgery protection for any json requests. This is required for jsonp support + skip_before_action :verify_authenticity_token + def index tracks = @conference ? @conference.program.tracks : Track.all