1
0
Fork 0
mirror of https://github.com/rails/rails.git synced 2022-11-09 12:12:34 -05:00
rails--rails/actionpack/test
Jose and Yehuda 56cdc81c08 Remove default match without specified method
In the current router DSL, using the +match+ DSL
method will match all verbs for the path to the
specified endpoint.

In the vast majority of cases, people are
currently using +match+ when they actually mean
+get+. This introduces security implications.

This commit disallows calling +match+ without
an HTTP verb constraint by default. To explicitly
match all verbs, this commit also adds a
:via => :all option to +match+.

Closes #5964
2012-04-24 22:52:26 -05:00
..
abstract Add a test case for layout nil. 2012-03-28 23:06:52 +04:00
activerecord Remove default match without specified method 2012-04-24 22:52:26 -05:00
assertions test response assertions 2012-01-06 11:20:26 -08:00
controller Remove default match without specified method 2012-04-24 22:52:26 -05:00
dispatch Remove default match without specified method 2012-04-24 22:52:26 -05:00
fixtures Make controller namespace partial prefix optional 2012-03-28 20:21:46 -04:00
lib/controller Removing old Controller test 2012-02-12 21:05:30 -02:00
routing add some tests, yay! 2012-02-22 11:05:03 -08:00
template Remove default match without specified method 2012-04-24 22:52:26 -05:00
tmp
abstract_unit.rb Remove default match without specified method 2012-04-24 22:52:26 -05:00
active_record_unit.rb
ts_isolated.rb AS/kernel/reporting no where used in ts_isolated 2012-03-04 21:30:48 +05:30