Repository navigation
docs(form): correct CSRF protection wording for SetAntiCsrfTrait - #361
Conversation
SetAntiCsrfTrait alone enforces token verification at every apply() call via DI + postConstruct(). The previous wording incorrectly stated that #[CsrfProtection] was required for verification. Document the two independent opt-in paths (per-form and per-action). Fixes #360
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
WalkthroughCSRF保護の説明を英語版・日本語版のform.mdドキュメントで更新。CSRF保護がopt-inであり、フォーム側のSetAntiCsrfTraitとアクション側の#[CsrfProtection]という2つの独立した有効化経路を持つことを明確化し、いずれの経路でもトークン不一致時に例外が発生すること、そして両経路を使わない場合は検証が行われないことを明記した。 ChangesCSRF保護opt-in仕様の明確化
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
Summary
Fixes #360.
The "CSRF Protections" / "CSRF" sections in
manuals/1.0/en/form.mdandmanuals/1.0/ja/form.mdincorrectly stated that#[CsrfProtection]was required for token verification when usingSetAntiCsrfTrait. In reality,SetAntiCsrfTraitalone enforces verification via DI +postConstruct()on everyapply()call.This PR applies the patch proposed in the issue, documenting the two independent opt-in paths:
use SetAntiCsrfTrait;— always-on for that form.#[CsrfProtection]on the controller method — interceptor injects antiCsrf beforeapply().Either path causes
AbstractForm::apply()to throwCsrfViolationExceptionon token mismatch.Test plan
manuals/1.0/en/form.md)manuals/1.0/ja/form.md)Generated by Claude Code
Summary by CodeRabbit
Release Notes
SetAntiCsrfTrait使用とアクション側での#[CsrfProtection]属性付与)と動作について明確化。