kemal-csrf
Version, currently 0.3.05 versions
- 0.5.0latestJun 18, 2018
- 0.4.0not indexedOct 18, 2019
- 0.3.0not indexedOct 18, 2019
- 0.2.0not indexedOct 18, 2019
- 0.1.0not indexedOct 18, 2019
github.com/fridgerator/kemal-csrf
Add CSRF protection to your Kemal application
Nothing has been indexed for 0.3.0 yet. The tag is recorded, its shard.yml has not been read, so the manifest and dependency list below are empty because they are unknown rather than because they are absent.
Installation
# Add this to your shard.yml
dependencies:
kemal-csrf:
github: fridgerator/kemal-csrf
version: ~> 0.3.0Then run:
shards installshard.yml
No shard.yml has been indexed for 0.3.0. You can read it on the repository.
Dependencies
Unknown: the shard.yml for this version has not been read yet.
README
This README is the one indexed from the repository at its latest ref, not from the tag for this version.
kemal-csrf
Adds CSRF protection to your Kemal application.
Requires a session middleware to be initialized first.
Installation
Add this to your application's shard.yml:
dependencies:
kemal-csrf:
github: kemalcr/kemal-csrf
Usage
Basic Use
require "kemal-csrf"
add_handler CSRF.new
You can also change the name of the form field, header name, the methods which don't need csrf,error message and routes which you don't want csrf to apply. All of these are optional
require "kemal-csrf"
add_handler CSRF.new(
header: "X_CSRF_TOKEN",
allowed_methods: ["GET", "HEAD", "OPTIONS", "TRACE"],
allowed_routes: ["/api/somecallback"],
parameter_name: "_csrf",
error: "CSRF Error"
)
If you need to have some logic within your error response, you can also pass it a proc (a pointer to a function)
require "kemal-csrf"
add_handler CSRF.new(
header: "X_CSRF_TOKEN",
allowed_methods: ["GET", "HEAD", "OPTIONS", "TRACE"],
allowed_routes: ["/api/somecallback"],
parameter_name: "_csrf",
error: ->myerrorhandler(HTTP::Server::Context)
)
def myerrorhandler(env)
if env.request.headers["Content-Type"]? == "application/json"
{"error" => "csrf error"}.to_json
else
"<html><head><title>Error</title><body><h1>You cannot post to this route without a valid csrf token</h1></body></html>"
end
end
Contributing
- Fork it ( https://github.com/kemalcr/kemal-csrf/fork )
- Create your feature branch (git checkout -b my-new-feature)
- Commit your changes (git commit -am 'Add some feature')
- Push to the branch (git push origin my-new-feature)
- Create a new Pull Request
Contributors
- sdogruyol Serdar Dogruyol - creator, maintainer
Documentation
Built from the current release. The first visit to a release nobody has asked for starts its build.
Links
This release
- Version
0.3.0- Tagged
- Oct 18, 2019
- Commit
abc88cce3f44- Indexed
- not yet
Dependents
No indexed shard depends on this one yet.
Repository
github.com/fridgerator/kemal-csrf
Metadata
- Created
- Aug 16, 2026
- Updated
- Aug 16, 2026
- Synced
- Aug 16, 2026
- Versions
- 5