4 ms·
I would recommend using CanCan for security if they haven't done so already so you can't just type in other users user_id in the url to view or edit. https://g
by ricksta 14y ago
I would recommend using CanCan for security if they haven't done so already so you can't just type in other users user_id in the url to view or edit.
https://github.com/ryanb/cancan https://github.com/ryanb/cancan
Cancan is great way to make sure that you can only read or edit your own records in the database with Rails.
- catch23 14y agoCancan probably wouldn't have prevented this. It's not because someone didn't use some library. The developer probably just did a User.find(params[:id]) instead of doing something like current_user from whatever authentication system they were using. He probably used the scaffolding generator to make everything and forgot to go back and ensure things are secure. It's also interesting that the aws key/secret are "masked" on the page, but you can just visit http://www.iceboxpro.com/users/12.json http://www.iceboxpro.com/users/12.json and get the formatted json representation with no masking.
- nathan_long 14y agoThis kind of thing can be handled with doing something like `current_user.accounts.find(params[:id)` instead of `accounts.find(params[:id])`. If it's not your resource, it's like it doesn't exist for you.