Re: [Catalyst] preventing Cross Site Request Forgery

2007-06-19 Thread Jonathan Rockway
On Tuesday 19 June 2007 09:47:50 am Matt S Trout wrote: > On Tue, Jun 19, 2007 at 07:11:10AM -0700, Bill Moseley wrote: > > On Tue, Jun 19, 2007 at 04:10:25AM -0500, Jonathan Rockway wrote: > > > http://www.25hoursaday.com/weblog/2007/06/05/WhatRubyOnRailsCanLearnFro > > >mASPNET.aspx > > > > > > a

Re: [Catalyst] preventing Cross Site Request Forgery

2007-06-19 Thread Matt S Trout
On Tue, Jun 19, 2007 at 07:11:10AM -0700, Bill Moseley wrote: > On Tue, Jun 19, 2007 at 04:10:25AM -0500, Jonathan Rockway wrote: > > http://www.25hoursaday.com/weblog/2007/06/05/WhatRubyOnRailsCanLearnFromASPNET.aspx > > > > and realized that Catalyst is just as "vulnerable" as Rails. So, I wrot

Re: [Catalyst] preventing Cross Site Request Forgery

2007-06-19 Thread Bill Moseley
On Tue, Jun 19, 2007 at 04:10:25AM -0500, Jonathan Rockway wrote: > http://www.25hoursaday.com/weblog/2007/06/05/WhatRubyOnRailsCanLearnFromASPNET.aspx > > and realized that Catalyst is just as "vulnerable" as Rails. So, I wrote > Catalyst::Plugin::FormCanary to solve the problem. If you care a

[Catalyst] preventing Cross Site Request Forgery

2007-06-19 Thread Jonathan Rockway
Hello cata-listers, I was reading an article about CSRF last night: http://www.25hoursaday.com/weblog/2007/06/05/WhatRubyOnRailsCanLearnFromASPNET.aspx and realized that Catalyst is just as "vulnerable" as Rails. So, I wrote Catalyst::Plugin::FormCanary to solve the problem. If you care about