canvas-lms/gems
James Williams e45ff7189a use double-cookie csrf protection
test plan:
* in one tab, start to fill out an ajax form
 (e.g. editing a quiz)
* in another tab, log out of canvas
* return to the original tab and try to
 submit the form (e.g. save your changes)
* should get an error message with a link to
 login in a new tab
* login in the new tab
* return to the original, and try to resubmit
* should save successfully

closes #CNVS-3957 #CNVS-13673

Change-Id: I7758514de8ce09361fef469034645d8a29e2a5e5
Reviewed-on: https://gerrit.instructure.com/40396
Reviewed-by: Jacob Fugal <jacob@instructure.com>
QA-Review: Clare Strong <clare@instructure.com>
Tested-by: Jenkins <jenkins@instructure.com>
Product-Review: Cosme Salazar <cosme@instructure.com>
2014-09-23 15:29:03 +00:00
..
active_polymorph set default scope for callbacks 2014-09-17 17:27:05 +00:00
activesupport-suspend_callbacks begin rails 4 2014-08-27 23:09:17 +00:00
acts_as_list begin rails 4 2014-08-27 23:09:17 +00:00
adheres_to_policy begin rails 4 2014-08-27 23:09:17 +00:00
attachment_fu rails4: gemify attachment_fu 2014-09-18 22:28:54 +00:00
bookmarked_collection begin rails 4 2014-08-27 23:09:17 +00:00
canvas_breach_mitigation use double-cookie csrf protection 2014-09-23 15:29:03 +00:00
canvas_cassandra align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
canvas_color extract color gem 2014-02-27 17:38:32 +00:00
canvas_crummy remove rails 2 support 2014-08-06 18:16:19 +00:00
canvas_ember_url align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
canvas_ext begin rails 4 2014-08-27 23:09:17 +00:00
canvas_http align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
canvas_kaltura bugfix: don't strip hyphens from media thumbnail URLs 2014-08-28 21:11:02 +00:00
canvas_mimetype_fu align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
canvas_quiz_statistics Quiz Stats - Multiple Answers 2014-06-05 09:12:19 +00:00
canvas_sanitize align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
canvas_slug clarify Slug vs. UUID and fix event stream 2014-07-11 16:58:42 +00:00
canvas_sort bundle check before bundle install for gem tests 2014-06-03 20:09:10 +00:00
canvas_statsd remove rails 2 support 2014-08-06 18:16:19 +00:00
canvas_stringex fix wiki_page_importer only_when_blank setting overwriting 2014-08-28 15:02:08 +00:00
canvas_text_helper align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
canvas_time begin rails 4 2014-08-27 23:09:17 +00:00
canvas_unzip add support for tar and tar.gz archives in content migrations 2014-08-01 12:36:27 +00:00
canvas_uuid clarify Slug vs. UUID and fix event stream 2014-07-11 16:58:42 +00:00
event_stream rework error handling in event stream 2014-08-28 21:19:24 +00:00
facebook align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
google_docs align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
handlebars_tasks align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
html_text_helper begin rails 4 2014-08-27 23:09:17 +00:00
i18n_extraction begin rails 4 2014-08-27 23:09:17 +00:00
i18n_tasks allow language mappings to be passed to transifex importer 2014-09-22 16:42:17 +00:00
incoming_mail_processor handle multipart incoming email with no html part 2014-09-11 22:30:45 +00:00
json_token align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
linked_in align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
lti_outbound add new ext_roles lti param for all the roles user has 2014-09-16 13:13:54 +00:00
multipart align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
paginated_collection align rspec version in gems with parent 2014-08-12 22:27:39 +00:00
plugins Gemspec for Academic Benchmarks gem uses a URI 2014-09-22 13:14:35 +00:00
twitter no more dynamic finders (gems) 2014-09-17 16:48:18 +00:00
utf8_cleaner begin rails 4 2014-08-27 23:09:17 +00:00
workflow begin rails 4 2014-08-27 23:09:17 +00:00
test_all_gems.sh spec: vendor_gems test.sh result determination tweak 2014-02-24 19:54:21 +00:00