On Sat, Feb 19, 2011 at 04:37, Jimmy <[email protected]> wrote:

> on our homepage we
> have a login form. Whether this login form has the authentication
> token or not doesn't matter anymore, login always succeeds. Even with
> cookies disabled. Previously it would not.


How is this a security flaw?  Login only succeeds if the credentials are
correct. If someone has credientials, they can login to the site, and I
don't see what role forged cross-site requests play in this case.

-- 
You received this message because you are subscribed to the Google Groups "Ruby 
on Rails: Core" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/rubyonrails-core?hl=en.

Reply via email to