4 ms·
> But for guys like me who never use mass assignment, our > applications are not vulnerable by default, correct? Yes, if you never ever call `update_attrib
by generalk 15y ago
> But for guys like me who never use mass assignment, our
> applications are not vulnerable by default, correct?
Yes, if you never ever call `update_attributes` you're not vulnerable. This is, however, the most common way to perform model updates.
> And likewise, for people who RTFM before using mass
> assignment, their applications are not vulnerable,
> correct?
No! Absolutely not! The Github exploit is a prime example of this. Solid developers, who have obviously ReadTFM, can easily fall victim to this because the default is to be insecure!
The fact is that Rails ships code generators that give you insecure code and put the onus on you to do something about it.
I'm not absolving any developer of their responsibility to not shoot themselves in the foot. Ultimately, if this Github exploit had been used to do serious damage, Github, not the Rails core team, would have been responsible. It is the developer's responsibility to ensure that their code is as free of vulnerabilities as they can make it.