3 ms·
Totally agree. The problem is the idiom of using mass assignment, which IMO should almost never be used. This is not a bug or a security hole in Rails, but an
by aneth 15y ago
Totally agree. The problem is the idiom of using mass assignment, which IMO should almost never be used.
This is not a bug or a security hole in Rails, but an issue with programmers not paying attention.
If Rails had no attr_accessible feature, it would be standard practice to always filter attributes in the controller, and no one would call this a rails issue - they would put the blame where it belongs: Github.
Instead, because attr_accessible exists, people are flaming that it should be enabled by default.