diff --git a/app/assets/javascripts/discourse/controllers/login_controller.js b/app/assets/javascripts/discourse/controllers/login_controller.js index 4b25e8f617..3cdbf674ff 100644 --- a/app/assets/javascripts/discourse/controllers/login_controller.js +++ b/app/assets/javascripts/discourse/controllers/login_controller.js @@ -56,7 +56,6 @@ Discourse.LoginController = Discourse.Controller.extend(Discourse.ModalFunctiona $hidden_login_form.find('input[name=username]').val(loginController.get('loginName')); $hidden_login_form.find('input[name=password]').val(loginController.get('loginPassword')); $hidden_login_form.find('input[name=redirect]').val(window.location.href); - $hidden_login_form.find('input[name=authenticity_token]').val($('meta[name=csrf-token]').attr('content')); $hidden_login_form.submit(); } diff --git a/app/controllers/static_controller.rb b/app/controllers/static_controller.rb index 6d6f434a88..6e5e81cf33 100644 --- a/app/controllers/static_controller.rb +++ b/app/controllers/static_controller.rb @@ -1,6 +1,7 @@ class StaticController < ApplicationController skip_before_filter :check_xhr, :redirect_to_login_if_required + skip_before_filter :verify_authenticity_token, only: [:enter] def show diff --git a/app/views/layouts/application.html.erb b/app/views/layouts/application.html.erb index 6ae0584d1d..49bde9e017 100644 --- a/app/views/layouts/application.html.erb +++ b/app/views/layouts/application.html.erb @@ -51,7 +51,6 @@ - <% end %>