3 ms·
Rails Security is apparently "omakase" - meaning 'leave it to someone else', apparently.
by static_typed 14y ago
Rails Security is apparently "omakase" - meaning 'leave it to someone else', apparently.
- wasd 14y agoDo you pose any interesting facts or thought to these discussions? I've seen you post in nearly every single one of these threads with nothing constructive. I understand that "you used to use Rails" and are much happier now that you're leaving the "insecure framework" but do you need to post it in every single thread? Disclaimer: I'm a java programmer.
- hakaaaaak 14y agoNot true, and I'm not a fan boy either. Did you read the security section of the guide? The edge one is more up to date (not just because its edge- the 3.x one needs love). Are you subscribed to the Rails security mailing list and core list? There is plenty to security that is not in the Rails documentation, though, and it is by no means bulletproof by any stretch of the imagination. If you don't take security seriously, then you increase the chance of getting stung. From exploits that you have to watch out for in your code, to setting up the server(s) and infrastructure in the most secure way that makes sense, it is a lot of work.