From d020eabf2938858830125ace467b13695eb85962 Mon Sep 17 00:00:00 2001 From: Douwe Maan Date: Fri, 28 Jul 2017 15:39:39 +0200 Subject: [PATCH] Add log messages to clarify log messages about API CSRF token verification failure --- lib/gitlab/request_forgery_protection.rb | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/lib/gitlab/request_forgery_protection.rb b/lib/gitlab/request_forgery_protection.rb index 48dd0487790..ccfe0d6bed3 100644 --- a/lib/gitlab/request_forgery_protection.rb +++ b/lib/gitlab/request_forgery_protection.rb @@ -7,6 +7,14 @@ module Gitlab class Controller < ActionController::Base protect_from_forgery with: :exception + rescue_from ActionController::InvalidAuthenticityToken do |e| + logger.warn "This CSRF token verification failure is handled internally by `GitLab::RequestForgeryProtection`" + logger.warn "Unlike the logs may suggest, this does not result in an actual 422 response to the user" + logger.warn "For API requests, the only effect is that `current_user` will be `nil` for the duration of the request" + + raise e + end + def index head :ok end