Change from hybrid to JSON cookies serializer
JSON has been the default serializer since Rails 4.1. Hybrid serializer was meant to allow backward compatibility when upgrading pre-Rails 4.1. It's been some time since we upgraded to Rails 4.1 so now we don't need the hybrid serializer anymore. This also causes security concerns since the previous serializer was Marshal.
显示
- changelogs/unreleased/security-dblessing-cookie-serializer.yml 5 个添加, 0 个删除...elogs/unreleased/security-dblessing-cookie-serializer.yml
- config/initializers/cookies_serializer.rb 2 个添加, 1 个删除config/initializers/cookies_serializer.rb
- spec/initializers/cookies_serializer_spec.rb 25 个添加, 0 个删除spec/initializers/cookies_serializer_spec.rb
加载中
想要评论请 注册 或 登录