3 ms·
This should not be an issue if you avoid mass-assignment with dumping all params, which is a security vulnerability anyway. If you do something like: @user =
by ejs 14y ago
This should not be an issue if you avoid mass-assignment with dumping all params, which is a security vulnerability anyway.
If you do something like:
@user = User.new(params[:user].slice(:name))
It will be safer, and avoid the problem.