kevinhughes27/ultimate-tournament

Security Vulnerability with compressed html

Closed this issue · 1 comments

Rafeal said this is the reason Rails doesn't use Rack::Deflate by default: http://breachattack.com/

Rafeal:
It is only an issue if you have a csrf token in the page, usually all rails pages has