CSRF
all
Only accepts unsafe HTTP requests if a given access token matches the token included in the session or the request comes from the same origin.
Compatible with Rails and rack-csrf.
# File lib/rack/protection/remote_token.rb, line 17 def accepts?(env) super or referrer(env) == Request.new(env).host end