diff --git a/Gemfile b/Gemfile index 205de4ccbe1..1c801d8f3f7 100644 --- a/Gemfile +++ b/Gemfile @@ -131,6 +131,12 @@ gem 'mini_racer' # TODO: determine why highline is being held back and upgrade to latest gem 'highline', '~> 1.7.0', require: false +# TODO: Upgrading breaks Sidekiq Web +# This is a bit of a hornets nest cause in an ideal world we much prefer +# if Sidekiq reused session and CSRF mitigation with Discourse on the +# _forum_session cookie instead of a rack.session cookie +gem 'rack', '2.0.8' + gem 'rack-protection' # security gem 'cbor', require: false gem 'cose', require: false diff --git a/Gemfile.lock b/Gemfile.lock index ce471e4d66e..8f38740bd1b 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -271,7 +271,7 @@ GEM puma (4.3.1) nio4r (~> 2.0) r2 (0.2.7) - rack (2.1.1) + rack (2.0.8) rack-mini-profiler (1.1.4) rack (>= 1.2.0) rack-openid (1.3.1) @@ -511,6 +511,7 @@ DEPENDENCIES pry-rails puma r2 + rack (= 2.0.8) rack-mini-profiler rack-protection rails_multisite