"Whereupon I learned that Rails 2.3.11 changed the behavior of CSRF protection: instead of throwing exceptions, it would silently just clear the session and re-run the request. For most sensitive operations (e.g. those which require a signed in user), this would force a signout and then any potentially damaging operation would be averted."
Doesn't this change a CSRF attempt into a DoS? I don't understand the logic behind this change. Why not return an error response?