On Fri, Nov 29, 2013 at 7:27 AM, Egor Homakov <homa...@gmail.com> wrote:

> @dhh as i mentioned above for GET request this will always be a security
> breach.
>

GET requests using Cookies for authentication. That returns non-public data.

-- 
You received this message because you are subscribed to the Google Groups "Ruby 
on Rails: Core" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to rubyonrails-core+unsubscr...@googlegroups.com.
To post to this group, send email to rubyonrails-core@googlegroups.com.
Visit this group at http://groups.google.com/group/rubyonrails-core.
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to