working on a tutorial for the scope injection / sql injection
This commit is contained in:
@@ -10,8 +10,9 @@ class AdminController < ApplicationController
|
||||
if params[:field].nil?
|
||||
fields = "*"
|
||||
else
|
||||
#fields = params[:field].map {|k,v| k }.join(",")
|
||||
fields = params[:field].map {|k,v| Analytics.parse_field(k) }.join(",")
|
||||
fields = params[:field].map {|k,v| k }.join(",")
|
||||
# This seems to be a bit safer
|
||||
#fields = params[:field].map {|k,v| Analytics.parse_field(k) }.join(",")
|
||||
end
|
||||
|
||||
if params[:ip]
|
||||
|
||||
Reference in New Issue
Block a user