<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0">
  <channel>
  <title>Jester JS Google Group</title>
  <link>http://groups.google.com/group/jester-js</link>
  <description>Discussion around Jester, a REST client written in JavaScript.</description>
  <language>en</language>
  <item>
  <title>Re: Speaking of recent Rails + Jester problems</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/daf9a08bdc29b013/e21a44c2f5c60b23?show_docid=e21a44c2f5c60b23</link>
  <description>
  Interesting. I think Jester should just commit to supporting the latest &lt;br&gt; standard, and forget about supporting the old attributes-only one. The &lt;br&gt; new JSON standard is closer to the XML standard, anyway. &lt;br&gt; -- Eric
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/daf9a08bdc29b013/e21a44c2f5c60b23?show_docid=e21a44c2f5c60b23</guid>
  <author>
  em...@thoughtbot.com
  (Eric Mill)
  </author>
  <pubDate>Fri, 22 Aug 2008 21:06:05 UT
</pubDate>
  </item>
  <item>
  <title>Speaking of recent Rails + Jester problems</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/daf9a08bdc29b013/a7ac5163cf05e134?show_docid=a7ac5163cf05e134</link>
  <description>
  Somewhere along the line - I&#39;m guessing in Rails 2.1 - the behavior of &lt;br&gt; ActiveRecord::Base#to_json seems to have changed. I&#39;ll give an &lt;br&gt; example - previously, doing something like user.to_json would have &lt;br&gt; returned something like: &lt;br&gt; {&amp;quot;nickname&amp;quot;: &amp;quot;&amp;quot;, &lt;br&gt; &amp;quot;lastname&amp;quot;: &amp;quot;Budin&amp;quot;, &lt;br&gt; &amp;quot;id&amp;quot;: 35, &lt;br&gt; &amp;quot;gender&amp;quot;: &amp;quot;male&amp;quot;, &lt;br&gt; &amp;quot;firstname&amp;quot;: &amp;quot;Nat&amp;quot;,
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/daf9a08bdc29b013/a7ac5163cf05e134?show_docid=a7ac5163cf05e134</guid>
  <author>
  natbu...@gmail.com
  (Nat Budin)
  </author>
  <pubDate>Fri, 22 Aug 2008 20:49:15 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/c9b237c1db493ed7?show_docid=c9b237c1db493ed7</link>
  <description>
  I don&#39;t know how often it changes, but I now have some indication that &lt;br&gt; this actually works in a real-world Rails use case. I modified my &lt;br&gt; JIPE plugin to support cross-site request forgery protection using &lt;br&gt; this patch, and cursory testing indicates that it works as intended. &lt;br&gt; For the curious, you can find my changed version at:
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/c9b237c1db493ed7?show_docid=c9b237c1db493ed7</guid>
  <author>
  natbu...@gmail.com
  (Nat Budin)
  </author>
  <pubDate>Fri, 22 Aug 2008 20:13:18 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/bde4ab093d3441ca?show_docid=bde4ab093d3441ca</link>
  <description>
  Ok, I see you responded. The forgery protection authenticity token &lt;br&gt; doesn&#39;t change with every new request? &lt;br&gt; -Chad &lt;br&gt; --- &lt;br&gt; Chad Pytel, Founder and CEO &lt;br&gt; thoughtbot, inc. &lt;br&gt; organic brains. digital solutions. &lt;br&gt; ------------------------------ ------------- &lt;br&gt; tel: 617.482.1300 x113 &lt;br&gt; fax: 866.217.5992 &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.thoughtbot.com&quot;&gt;[link]&lt;/a&gt;
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/bde4ab093d3441ca?show_docid=bde4ab093d3441ca</guid>
  <author>
  cpy...@thoughtbot.com
  (Chad Pytel)
  </author>
  <pubDate>Fri, 22 Aug 2008 20:00:35 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/c2ac21fc024a453d?show_docid=c2ac21fc024a453d</link>
  <description>
  I agree, and its something that exists in Active Resource as well. I &lt;br&gt; remain to convinced that it&#39;ll actually work to solve the authenticity &lt;br&gt; token, because I still don&#39;t know how you get it from the server, but &lt;br&gt; thats without doing any research on it either. &lt;br&gt; -Chad &lt;br&gt; --- &lt;br&gt; Chad Pytel, Founder and CEO
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/c2ac21fc024a453d?show_docid=c2ac21fc024a453d</guid>
  <author>
  cpy...@thoughtbot.com
  (Chad Pytel)
  </author>
  <pubDate>Fri, 22 Aug 2008 19:58:43 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/1282afe0aa894ac8?show_docid=1282afe0aa894ac8</link>
  <description>
  Nat, you are a badass. &lt;br&gt; -- Eric
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/1282afe0aa894ac8?show_docid=1282afe0aa894ac8</guid>
  <author>
  em...@thoughtbot.com
  (Eric Mill)
  </author>
  <pubDate>Fri, 22 Aug 2008 19:26:36 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/ef5b693eebfa622b?show_docid=ef5b693eebfa622b</link>
  <description>
  The proposed solution, setting default URL parameters for each request, &lt;br&gt; is something useful in general, that would also help with the Rails &lt;br&gt; authenticity token issue. Allowing URL parameters to be passed on &lt;br&gt; -- Eric
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/ef5b693eebfa622b?show_docid=ef5b693eebfa622b</guid>
  <author>
  em...@thoughtbot.com
  (Eric Mill)
  </author>
  <pubDate>Fri, 22 Aug 2008 19:06:55 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/49d962ea1b160ee6?show_docid=49d962ea1b160ee6</link>
  <description>
  OK, forked, modified, pull request sent. Also includes unit tests! &lt;br&gt; This turned out to be somewhat more straightforward than I thought: &lt;br&gt; everything except obj.save is already using the _url_for helpers, and &lt;br&gt; already accepts arbitrary parameters being passed in. So all I needed &lt;br&gt; to modify was the _url_for function (to support model._defaultParams),
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/49d962ea1b160ee6?show_docid=49d962ea1b160ee6</guid>
  <author>
  natbu...@gmail.com
  (Nat Budin)
  </author>
  <pubDate>Fri, 22 Aug 2008 19:05:02 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/bb994040ebb1225d?show_docid=bb994040ebb1225d</link>
  <description>
  Thanks, Eric! I&#39;ll try and do a fork later today and see what I can &lt;br&gt; come up with. &lt;br&gt; Nat
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/bb994040ebb1225d?show_docid=bb994040ebb1225d</guid>
  <author>
  natbu...@gmail.com
  (Nat Budin)
  </author>
  <pubDate>Fri, 22 Aug 2008 17:31:25 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/e43c98071f78306f?show_docid=e43c98071f78306f</link>
  <description>
  It&#39;s easy: &lt;br&gt; &amp;lt;%= form_authenticity_token %&amp;gt; &lt;br&gt; Or if you want to be more sophisticated: &lt;br&gt; &amp;lt;% if protect_from_forgery? -%&amp;gt; &lt;br&gt; &amp;lt;%= form_authenticity_token %&amp;gt; &lt;br&gt; &amp;lt;% end -%&amp;gt; &lt;br&gt; Nat
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/e43c98071f78306f?show_docid=e43c98071f78306f</guid>
  <author>
  natbu...@gmail.com
  (Nat Budin)
  </author>
  <pubDate>Fri, 22 Aug 2008 17:26:36 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/ab5764efc1e3c596?show_docid=ab5764efc1e3c596</link>
  <description>
  I don&#39;t know how you can even find out the authenticity token from &lt;br&gt; rails. This would be key to get that to work, as far as I know it &lt;br&gt; changes for every request. In my opinion, this is really more of a &lt;br&gt; rails problem, then something for jester to solve with a custom &lt;br&gt; solution.
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/ab5764efc1e3c596?show_docid=ab5764efc1e3c596</guid>
  <author>
  cpy...@thoughtbot.com
  (Chad Pytel)
  </author>
  <pubDate>Fri, 22 Aug 2008 17:25:01 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/3594fe5a1fd98ee7?show_docid=3594fe5a1fd98ee7</link>
  <description>
  You&#39;re right, Nat. I think the solution here is as you suggest, adding &lt;br&gt; the ability to pass along arbitrary URL parameters to all actions, not &lt;br&gt; just #find. &lt;br&gt; Perhaps specifying a default set of accompanying URL params (in other &lt;br&gt; frameworks, this might be a &amp;quot;jsessionid&amp;quot;, etc.) on the Resource &lt;br&gt; definition would work too. I envision that looking just like:
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/3594fe5a1fd98ee7?show_docid=3594fe5a1fd98ee7</guid>
  <author>
  em...@thoughtbot.com
  (Eric Mill)
  </author>
  <pubDate>Fri, 22 Aug 2008 15:04:07 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/1aa8b8258c622f79?show_docid=1aa8b8258c622f79</link>
  <description>
  That would certainly work, but it seems like a bad idea to just &lt;br&gt; disable those protections. Do we really want to encourage people to &lt;br&gt; turn off security features for the sake of coding convenience? &lt;br&gt; Nat
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/1aa8b8258c622f79?show_docid=1aa8b8258c622f79</guid>
  <author>
  natbu...@gmail.com
  (Nat Budin)
  </author>
  <pubDate>Thu, 21 Aug 2008 18:59:45 UT
</pubDate>
  </item>
  <item>
  <title>Re: Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/b378053d72c3d2c0?show_docid=b378053d72c3d2c0</link>
  <description>
  As with normal Active Resource, it&#39;s expected that you disable forgery &lt;br&gt; protection for resources that will be accessed.
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/b378053d72c3d2c0?show_docid=b378053d72c3d2c0</guid>
  <author>
  cpy...@thoughtbot.com
  (Chad Pytel)
  </author>
  <pubDate>Thu, 21 Aug 2008 18:46:10 UT
</pubDate>
  </item>
  <item>
  <title>Jester and Rails&#39;s forgery protection</title>
  <link>http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/98366c33052b8af8?show_docid=98366c33052b8af8</link>
  <description>
  Hello everyone! &lt;br&gt; As of Rails 2.0, there is an optional (but turned on by default in new &lt;br&gt; apps) mechanism for doing cross-site request forgery (CSRF) &lt;br&gt; protection. This article provides a decent overview of how it works: &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://baseunderattack.com/2008/04/18/ruby-on-rails-and-csrf-protection/&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; Unfortunately this seems to cause some problems for Jester when turned
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/jester-js/browse_thread/thread/6689dc6867a31ace/98366c33052b8af8?show_docid=98366c33052b8af8</guid>
  <author>
  natbu...@gmail.com
  (Nat Budin)
  </author>
  <pubDate>Thu, 21 Aug 2008 18:41:18 UT
</pubDate>
  </item>
  </channel>
</rss>
