Public Instance methods
check_sec_fetch_site!(&block)
Check that the Sec-Fetch-Site header is valid, if the request requires it. If the header is valid or the request does not require the header, return nil. Otherwise, if a block is given, treat it as a routing block and yield to it, and if a block is not given, use the plugin :csrf_failure option to determine how to handle it.
[show source]
# File lib/roda/plugins/sec_fetch_site_csrf.rb 103 def check_sec_fetch_site!(&block) 104 plugin_opts = self.class.opts[:sec_fetch_site_csrf] 105 return unless plugin_opts[:check_request_methods].include?(request.request_method) 106 107 sec_fetch_site = env["HTTP_SEC_FETCH_SITE"] 108 return if plugin_opts[:allowed_values].include?(sec_fetch_site) 109 110 @_request.on(&block) if block 111 112 case failure_action = plugin_opts[:csrf_failure] 113 when :raise 114 raise CsrfFailure, "potential cross-site request, Sec-Fetch-Site value: #{sec_fetch_site.inspect}" 115 when :empty_403 116 @_response.status = 403 117 headers = @_response.headers 118 headers.clear 119 headers[RodaResponseHeaders::CONTENT_TYPE] = 'text/html' 120 headers[RodaResponseHeaders::CONTENT_LENGTH] ='0' 121 throw :halt, @_response.finish_with_body([]) 122 when :clear_session 123 # RODA4: Remove 124 session.clear 125 else # when :method 126 @_request.on{_roda_sec_fetch_site_csrf_failure(@_request)} 127 end 128 end