We have written an extensive blog on what CSRF is and what steps Rails 4 takes to prevent CSRF. We encourage you to read that blog to fully understand rest of this article.
Nested form can get around CSRF protection offered by Rails 4
A typical form generated in Rails 4 might look like this.
1 2<form method= "post" action="/money_transfer"> 3 <input type="hidden" name="authenticity_token" value="token_value"> 4</form> 5
1 2<form method="post" action="http://www.fraud.com/fraud"> 3 <form method= "post" action="/money_transfer"> 4 <input type="hidden" name="authenticity_token" value="token_value"> 5 </form> 6</form> 7
HTML specification does not allow nested forms.
Since nested forms are not allowed browser will accept the top most level form. In this case that happens to be the form created by the hacker. When this form is submitted then "authenticity_token" is also submitted and Rails will do its check and will say everything is looking good and thus hacker will be able to hack the site.
Rails 5 fixes the issue by generating a custom token for a form
In Rails 5, CSRF token can be added for each form. Each CSRF token will be valid only for the method/action of the form it was included in.
You can add following line to your controller to add authenticity token specific to method and action in each form tag of the controller.
1 2class UsersController < ApplicationController 3 self.per_form_csrf_tokens = true 4end 5
Adding that code to each controller feels burdensome. In that case you can enable this behavior for all controllers in the application by adding following line to an initializer.
1 2# config/application.rb 3Rails.configuration.action_controller.per_form_csrf_tokens = true 4
This will add authenticity token specific to method and action in each form tag of the application. After adding that token the generated form might look like as shown below.
1 2<form method= "post" action="/money_transfer"> 3 <input type="hidden" name="authenticity_token" value="money_transfer_post_action_token"> 4</form> 5
Authenticity token included here will be specific to action
money_transfer and method
Attacker can still grab authenticity_token here, but attack will be limited to
money_transfer post action.