Rails安全警告 - 秘密选项

时间:2013-01-11 04:01:42

标签: ruby-on-rails ruby security

  

可能重复:
  No secret option provided to Rack::Session::Cookie warning?

我刚刚创建了一个新的rails 3.2.8 app并运行了以下命令

 rails g paperclip myModel image

之后我收到此警告

  SECURITY WARNING: No secret option provided to Rack::Session::Cookie.
    This poses a security threat. It is strongly recommended that you
    provide a secret to prevent exploits that may be possible from crafted
    cookies. This will not be supported in future versions of Rack, and
    future versions will even invalidate your existing user cookies.

这一切都很好,但我应该怎么做呢。任何想法

由于

1 个答案:

答案 0 :(得分:1)

见这里:

No secret option provided to Rack::Session::Cookie warning?

您也可能希望立即升级到Rails 3.2.11以修补最近发现的一些安全漏洞。