4 ms·
Yes, but it gets protected automatically if you use the mentioned attr_protected or the accessible version. Basic Rails code to update your own details on the
by fendale 19y ago
Yes, but it gets protected automatically if you use the mentioned attr_protected or the accessible version.
Basic Rails code to update your own details on the 'view my details' screen is something like
def update_details
@logged_in_user = User.find_by_id(session[:userid])
@logged_in_user.update_attrs(params[:user])
@logged_in_user.save
end
Obviously you would never expose the :is_admin flag on the update_details screen, but a not even very cunning user could guess its there and manufacture up a post request containing the is_admin flag, setting it using the bulk assignment above.
Sticking in attr_protected :is_admin in your model means that ActiveRecord will just ignore that attribute if it is bulk assigned securing it with a single line of code.
Attr_accessible was new in Rails 2 (I think) - its says deny all BUT the ones listed - best way by far.
- timr 19y agofyi: the save is redundant. update_attributes saves the record for you.
- deleted 19y ago[deleted]