github / github/codespaces-rails

AuthenticityToken Missmatch on CRUD after Port Forwarding

未關閉
#37 1 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Ruby
星號
148
分支
121
平均合併
4 天 12 小時
30 天內合併 PR
2

描述

I am encountering forgery protection issue when I try to do regular CRUD operations that connected to postgres like normal, so everytime I did POST action, the console throws message below:

```
ActionController::InvalidAuthenticityToken (HTTP Origin header (http://localhost:3000) didn't match request.base_url (https://{space-name}-{space-id}-3000.app.github.dev)
```

So far, [this answer (22965)](https://github.com/rails/rails/issues/22965#issuecomment-172983268) can solve the problem, which suggest to add:

```ruby
config.action_controller.forgery_protection_origin_check = false
```
to _development.rb_, or put

```ruby
skip_forgery_protection
```
on _application_controller.rb_

I still feel uncomfortable with this approach since I can't do the rails standards, I've been doing this just fine in another IDE like **Gitpod** or **AWS Cloud9**, but it's just different here. I'm trying figuring out on the VM level try to modify nginx config until I realize that codespaces service might run inside a container LOL. I still think that this because I'm not sure how port forwarding works in this service, but if that's the reason, why I can still access the app only with GET requests?

Some help/ guidance from official team would be nice!

cc @joshaber @samruddhikhandale @bdmac

貢獻指南

開啟貢獻指南

研究方向

Start by reproducing the POST failure in the Codespaces port-forwarded app and inspect the development.rb and application_controller.rb options mentioned in the report. Compare the forwarded request origin with request.base_url and examine the nginx or container port-forwarding configuration; done means identifying the configuration mismatch and documenting a standards-compliant fix without disabling forgery protection.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
rails, ruby
領域
backend, infrastructure, security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
需要釐清
新手友好度
30/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。