Change #{a} and #{form} have the option to use authenticity token

Bug #579264 reported by Dave Cheong
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
play framework
Won't Fix
Undecided
Unassigned
1.0
Won't Fix
Undecided
Unassigned
1.1
Fix Committed
Undecided
Unassigned

Bug Description

In order to make our sites secure from CSRF, an authenticity token is required. This is currently not possible via the #{a} or #{form} tags. This bug is to change #{a} and #{form} to set the authenticity token by default, with an optional switch to turn it off.

See for further information:
http://groups.google.com/group/play-framework/browse_thread/thread/8a9b45dd0af86414

A patch to FastTags is provided as an attachment in this bug report.

Revision history for this message
Dave Cheong (dc-davecheong) wrote :
visibility: private → public
Revision history for this message
Dave Cheong (dc-davecheong) wrote :

Path to _a() and _form() with exclusion of the "authentic" attribute from the rendered output

Changed in play:
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.