Skip to content

Commit 855f92d

Browse files
committed
Use omniauth-rails_csrf_protection gem
It seems like omniauth-rails is not actually the correct gem: omniauth/omniauth-rails#2 (comment) Here's the relevant instructions: https://github.com/omniauth/omniauth/wiki/Resolving-CVE-2015-9284
1 parent 4dca054 commit 855f92d

File tree

2 files changed

+5
-11
lines changed

2 files changed

+5
-11
lines changed

Gemfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ gem 'jbuilder'
1818
gem 'jquery-rails'
1919
gem 'memcachier'
2020
gem 'omniauth-facebook'
21-
gem 'omniauth-rails', git: 'https://github.com/omniauth/omniauth-rails', branch: 'CVE-2015-9284'
21+
gem 'omniauth-rails_csrf_protection'
2222
gem 'pg'
2323
gem 'pry-rails'
2424
gem 'puma'

Gemfile.lock

Lines changed: 4 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,3 @@
1-
GIT
2-
remote: https://github.com/omniauth/omniauth-rails
3-
revision: 8ef80e7da0b4b12dd403ba579b0a34dd6efebdae
4-
branch: CVE-2015-9284
5-
specs:
6-
omniauth-rails (1.0.0)
7-
omniauth (~> 1.0)
8-
rails
9-
101
GEM
112
remote: https://rubygems.org/
123
specs:
@@ -193,6 +184,9 @@ GEM
193184
omniauth-oauth2 (1.5.0)
194185
oauth2 (~> 1.1)
195186
omniauth (~> 1.2)
187+
omniauth-rails_csrf_protection (0.1.2)
188+
actionpack (>= 4.2)
189+
omniauth (>= 1.3.1)
196190
parallel (1.20.1)
197191
parser (3.0.1.1)
198192
ast (~> 2.4.1)
@@ -372,7 +366,7 @@ DEPENDENCIES
372366
memcachier
373367
oj
374368
omniauth-facebook
375-
omniauth-rails!
369+
omniauth-rails_csrf_protection
376370
pg
377371
pry-rails
378372
puma

0 commit comments

Comments
 (0)