recover from bad CSRF tokens without requiring a hard refresh of the browser

This commit is contained in:
Sam
2013-08-27 15:56:12 +10:00
parent bec463564f
commit c4a0152dc6
5 changed files with 16 additions and 9 deletions

View File

@ -67,7 +67,7 @@ class SessionController < ApplicationController
end
def destroy
session[:current_user_id] = nil
reset_session
cookies[:_t] = nil
render nothing: true
end