mass assignment vulnerability, how it manifests in Rails 4
This commit is contained in:
@@ -55,7 +55,7 @@ class UsersController < ApplicationController
|
|||||||
private
|
private
|
||||||
|
|
||||||
def user_params
|
def user_params
|
||||||
params.require(:user).permit(:email, :admin, :first_name, :last_name, :user_id, :password, :password_confirmation)
|
params.require(:user).permit!
|
||||||
end
|
end
|
||||||
|
|
||||||
# unpermitted attributes are ignored in production
|
# unpermitted attributes are ignored in production
|
||||||
|
|||||||
Reference in New Issue
Block a user