Skip to content

Skip CSRF for reject (token-authenticated, no session) - #2999

Merged
mroderick merged 1 commit into
codebar:masterfrom
mroderick:fix/reject-token-no-session
Oct 9, 2026
Merged

mroderick merged 1 commit into
codebar:masterfrom
mroderick:fix/reject-token-no-session

Conversation

@mroderick

@mroderick mroderick commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

The reject endpoint authenticates by the invitation token in the URL. Unlike accept and update, it still
enforced CSRF — so a browser withholding the session cookie (for example Safari/WebKit ITP on cross-site
navigation) gets InvalidAuthenticityToken. This PR adds reject to the skip_forgery_protection
list and pins the token-only, no-session request.

One of five small PRs from the same pre-existing-gap audit against this flow. Heads are reviewed independently; if a sibling merges first expect a trivial rebase.

Detail

The mismatch showed up when writing the no-session spec: on master the spec fails with ActionController::InvalidAuthenticityToken. Join and leave (WaitingListsController#create/destroy) are already skipped and covered by analogous specs; reject is the odd one out.

Review notes

Sibling PRs:

The reject endpoint authenticates by the invitation token in the URL,
like accept and update. Its form must survive a browser withholding the
session cookie (e.g. Safari/WebKit ITP on cross-site navigation), but
with CSRF protection enforced reject fails with
InvalidAuthenticityToken before the token can do its job.

Add reject to the skip_forgery_protection list, matching accept, update
and WaitingListsController (same rationale as PR codebar#2641, Rollbar codebar#535),
and pin the token-only, no-session request with a spec.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant