Security Vulnerability with compressed html
Closed this issue · 1 comments
kevinhughes27 commented
Rafeal said this is the reason Rails doesn't use Rack::Deflate by default: http://breachattack.com/
kevinhughes27 commented
Rafeal:
It is only an issue if you have a csrf token in the page, usually all rails pages has