4 ms·
Blanket accepting POST data to insert into your database is a terrible idea. Rails gives you attr_accessible and attr_protected to alleviate this problem. Prot
by Pewpewarrows 14y ago
Blanket accepting POST data to insert into your database is a terrible idea.
Rails gives you attr_accessible and attr_protected to alleviate this problem. Protip: the one from those two that you suggested to use is just as terrible an idea as allowing blind POST into your database. Blacklisting is always the wrong approach to security. I don't care if you have to repeat yourself and type more characters: use the whitelisting of attr_accessible.
- ef4 14y agoBut even if they're using attr_accessible to whitelist parameters, the failure mode here would have been exactly the same. The real culprit is Apple. It's just not ok to add unexpected parameters to people's POSTs. If anything, they should have put it in an HTTP header instead.
- Pewpewarrows 14y agoI'm a Python/Django guy so I'm not intimately familiar, but is that really the case? I was under the assumption that the handler wouldn't pass any POST vars not in attr_accessible to the model. In which case additional, unexpected ones would become silently dropped.
- masklinn 14y agoAccording to http://guides.rubyonrails.org/security.html#countermeasures http://guides.rubyonrails.org/security.html#countermeasures you're entirely correct that it won't raise any error, although the keys won't be dropped: attr_accessible drops the attributes when mass-assigned to a model, they're still available in the params hash.