4 ms·
I find it interesting that DHH dismissed this out-of-hand given Egor's history with Rails. In his tweets he highlights some pretty large Rails projects that imp
by purephase 13y ago
I find it interesting that DHH dismissed this out-of-hand given Egor's history with Rails. In his tweets he highlights some pretty large Rails projects that impact a lot of users/sites.
I know a few of my own are affected by this.
- homakov 13y agoHe dismisses removal of it. He just wants to find a painless way to fix security concern. I don't know such way
- KayEss 13y agoI suppose this won't work for RJS, but for other similar JSONP vulnerabilities the correct approach is probably to strip out authentication from JSONP requests -- this could be done at the middleware layer or where authentication happens. Now JSONP would only leak data that you'd give to any other anonymous user.
- homakov 13y agoNot perfect though. Intranet leaks
- po 13y agoIt's clear that the author is frustrated though. Maybe it's just me but I feel like a framework's core team should treat security vulnerabilities (or even common design patterns that lead to them) as stop-the-world events until they are resolved. It's not up to the issue reporter to come up with a fix that satisfies the core team.
- homakov 13y agoHaha i practised pull request fixing zero days for a while. Ppl asked me to stop