3 ms·
I agree the syntax for strong_params is confusing and error prone, but I wish the author had drawn more of a distinction between the schema of the request paylo
by mnutt 4y ago
I agree the syntax for strong_params is confusing and error prone, but I wish the author had drawn more of a distinction between the schema of the request payload versus the schema of the model. Rails assumes the model should handle its own type validations, and strong_params is sort of a bandaid to ensure the params object can’t affect internal implementation details. dry_schema looks way more powerful but it makes it easier for one to forget that the primary goal is not a generalized schema, but a security boundary for ensuring dangerous attributes aren’t set on the model.
I think the pattern is helpful but it’s still pretty easy to mess up.