Issues
- 0
Mention the migration in GitHub Pages
#123 opened by FranklinYu - 1
How can I update AuthenticityToken automatically?
#119 opened by dehengxu - 4
Forbidden + signout using sidekiq/devise/activeadmin on production server with nginx/haproxy/thin
#107 opened by ysynesis - 6
- 7
New stable release before merging?
#118 opened by astratto - 2
Could not find gem 'rack-protection' in git://github.com/sinatra/rack-protection.git (at master@f405fec)
#117 opened by jaredbeck - 1
Mask CSRF tokens to mitigate BREACH attack
#64 opened by louismullie - 3
AuthenticityToken
#106 opened by hojberg - 4
JsonCsrf for GET image.
#84 opened by georgeu2000 - 2
[Warning] Session Hijacking default of HTTP_ACCEPT_LANGUAGE is broken for iOS 8+
#88 opened by tommeier - 2
Is AuthenticityToken broken?
#100 opened by odigity - 2
Rack::Protection::SessionHijacking
#92 opened by frodsan - 2
- 3
Invalid URI causes exception
#82 opened by rb2k - 2
Please add changelog
#79 opened by PikachuEXE - 1
Whitelist for JsonCsrf
#63 opened by rsiddle - 5
Invalid referer raises error
#61 opened by georgeu2000 - 0
Cookie protection, ala Github's blog post
#53 opened by nogweii - 3
Add documentation
#55 opened by m-o-e - 1
X-XSS-Protection also applies to chrome
#48 opened by oreoshake - 0
Regenerate docs
#109 opened by zzak - 6
"You need to set up a session middleware *before* Rack::Protection::SessionHijacking"
#77 opened by rickygu - 3
escaped params silently removing files
#90 opened by danleyden - 7
Silently Ignore Lack of Session Middleware
#47 opened by Wardrop - 11
Don't autoload?
#45 opened by charlie - 1
Sinatra problem with rack-protection
#110 opened by pamit - 4
undefined method `[]' for nil:NilClass
#103 opened by beanieboi - 3
Consider changing the repo description
#101 opened by adelevie - 2
- 2
Homepage link is broken
#94 opened by zzak - 1
Token changes between retrieval and request
#89 opened by cmouse - 1
- 5
- 1
[Readme] Instrumentation example
#81 opened by tommeier - 2
- 7
- 2
content-type-security header
#72 opened by mkristian - 24
undefined method `detect' for nil:NilClass
#50 opened by blambeau - 1
- 4
License missing from gemspec
#62 opened by bf4 - 2
- 1
What is meant by "rack-csrf" compatibility?
#67 opened by da99 - 2
Implementation doubt
#59 opened by sonoman - 1
nosniff should be set non html content as well
#40 opened by mkristian - 1
CORS and JSON_CSRF
#39 opened by resistorsoftware - 1
Block remote requests from non-HTTP pages
#44 opened by louismullie - 2
- 4
undefined method `base_url'
#36 opened by patsanch - 0
- 2
undefined method `last' for nil:NilClass
#34 opened by hron84