Skip to content

docs(form): correct CSRF protection wording for SetAntiCsrfTrait - #361

Merged
koriym merged 1 commit into
masterfrom
claude/fix-issue-wC4sV
May 21, 2026
Merged

koriym merged 1 commit into
masterfrom
claude/fix-issue-wC4sV

Conversation

@koriym

@koriym koriym commented May 19, 2026 •

Copy link
Copy Markdown
Member

Summary

Fixes #360.

The "CSRF Protections" / "CSRF" sections in manuals/1.0/en/form.md and manuals/1.0/ja/form.md incorrectly stated that #[CsrfProtection] was required for token verification when using SetAntiCsrfTrait. In reality, SetAntiCsrfTrait alone enforces verification via DI + postConstruct() on every apply() call.

This PR applies the patch proposed in the issue, documenting the two independent opt-in paths:

  • Per-form: use SetAntiCsrfTrait; — always-on for that form.
  • Per-action: #[CsrfProtection] on the controller method — interceptor injects antiCsrf before apply().

Either path causes AbstractForm::apply() to throw CsrfViolationException on token mismatch.

Test plan

  • EN docs updated (manuals/1.0/en/form.md)
  • JA docs updated (manuals/1.0/ja/form.md)
  • Preview renders correctly on the docs site after merge

Generated by Claude Code

Summary by CodeRabbit

Release Notes

  • Documentation
    • CSRF保護機能に関するドキュメントを更新。opt-in有効化の2つの方法(フォーム側での SetAntiCsrfTrait 使用とアクション側での #[CsrfProtection] 属性付与)と動作について明確化。

Review Change Stack

SetAntiCsrfTrait alone enforces token verification at every apply() call
via DI + postConstruct(). The previous wording incorrectly stated that
#[CsrfProtection] was required for verification. Document the two
independent opt-in paths (per-form and per-action).

Fixes #360
@coderabbitai

coderabbitai Bot commented May 19, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 6b4fb099-0396-40be-b43c-41a8b866cb57

📥 Commits

Reviewing files that changed from the base of the PR and between 5903384 and 5a65a9a.

📒 Files selected for processing (2)
  • manuals/1.0/en/form.md
  • manuals/1.0/ja/form.md

Walkthrough

CSRF保護の説明を英語版・日本語版のform.mdドキュメントで更新。CSRF保護がopt-inであり、フォーム側のSetAntiCsrfTraitとアクション側の#[CsrfProtection]という2つの独立した有効化経路を持つことを明確化し、いずれの経路でもトークン不一致時に例外が発生すること、そして両経路を使わない場合は検証が行われないことを明記した。

Changes

CSRF保護opt-in仕様の明確化

レイヤー / ファイル 説明
CSRF保護opt-inの2経路と例外動作を説明
manuals/1.0/en/form.md, manuals/1.0/ja/form.md
フォーム単位でSetAntiCsrfTraitを使う経路とアクション単位で#[CsrfProtection]を付与する経路を整理。どちらの経路でもAbstractForm::apply()がトークン不一致時にCsrfViolationExceptionをthrowすること、両経路がない場合はCSRF検証が行われないことを明確化した。

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • bearsunday/bearsunday.github.io#358: Ray WebForm 1.0マニュアルのCSRF関連セクションを更新し、opt-inメカニズム(SetAntiCsrfTraitと#[CsrfProtection]の関係およびCSRF検証動作)を調整・明確化しているPR。
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PR title accurately summarizes the main change: correcting CSRF protection documentation regarding SetAntiCsrfTrait behavior.
Linked Issues check ✅ Passed The PR fully addresses issue #360 by correcting the CSRF protection documentation in both EN and JA manuals to clarify two independent opt-in paths and proper token verification behavior.
Out of Scope Changes check ✅ Passed All changes are limited to documentation files (manuals/1.0/en/form.md and manuals/1.0/ja/form.md) and directly address the linked issue requirements.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/fix-issue-wC4sV

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@koriym
koriym marked this pull request as ready for review May 21, 2026 10:08
@koriym

koriym commented May 21, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 21, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@koriym
koriym merged commit 2e29545 into master May 21, 2026
@koriym
koriym deleted the claude/fix-issue-wC4sV branch May 21, 2026 10:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(form): CSRF protection description is incorrect — SetAntiCsrfTrait alone enforces verification

2 participants