Welcome Guest, Not a member yet? Register   Sign In
Security Class "The action you have requested is not allowed."
#4

[eluser]megabyte[/eluser]
Is it possible to turn on csrf protection on a per controller basis?

I'd want it on forms that do not require authentication, but once a user is logged it should not matter as much.

Thats the only solution apart from having a meta refresh set to the session expire time so that there would never be an instance where the user would be logged in and see a form but have an expired session.


Messages In This Thread
Security Class "The action you have requested is not allowed." - by El Forum - 01-30-2011, 10:09 PM



Theme © iAndrew 2016 - Forum software by © MyBB