Mike Dalessio 41675224d0 Remove redundant insecure context CSRF check
Rails now handles the insecure context case natively in
verified_via_header_only? — when Sec-Fetch-Site is missing and the
request is plain HTTP without force_ssl, the request is allowed.

Remove the now-redundant allowed_insecure_context_request? method and
update the test to set ActionDispatch::Http::URL.secure_protocol
alongside Rails.configuration.force_ssl so the upstream check works
correctly in the test environment.
2026-02-18 14:06:46 -05:00
2024-06-21 13:19:56 +01:00
2025-12-02 13:35:58 -08:00
2024-06-21 13:19:56 +01:00
2024-06-21 13:19:56 +01:00
2025-11-21 09:15:19 +00:00
2025-12-04 09:59:17 -08:00
2025-10-09 13:24:01 -07:00
2026-02-02 19:31:12 +01:00
2025-12-02 20:37:58 +01:00
2025-11-28 15:53:58 +01:00
2024-06-21 16:42:48 +01:00
2025-12-12 17:26:50 +00:00

Fizzy

This is the source code of Fizzy, the Kanban tracking tool for issues and ideas by 37signals.

Running your own Fizzy instance

If you want to run your own Fizzy instance, but don't need to change its code, you can use our pre-built Docker image. You'll need access to a server on which you can run Docker, and you'll need to configure some options to customize your installation.

You can find the details of how to do a Docker-based deployment in our Docker deployment guide.

If you want more flexibility to customize your Fizzy installation by changing its code, and deploy those changes to your server, then we recommend you deploy Fizzy with Kamal. You can find a complete walkthrough of doing that in our Kamal deployment guide.

Development

You are welcome -- and encouraged -- to modify Fizzy to your liking. Please see our Development guide for how to get Fizzy set up for local development.

Contributing

We welcome contributions! Please read our style guide before submitting code.

License

Fizzy is released under the O'Saasy License.

S
Description
No description provided
Readme 62 MiB
Languages
Ruby 67.8%
HTML 14.6%
CSS 10.8%
JavaScript 5.6%
Shell 0.9%
Other 0.3%