aboutsummaryrefslogtreecommitdiffstats
path: root/RELEASING_RAILS.rdoc
diff options
context:
space:
mode:
authordevlin zed <me@devlinzed.com>2014-02-11 10:44:45 -0500
committerdevlin zed <me@devlinzed.com>2014-02-11 10:44:45 -0500
commitec0664a6eb8906fcd31a53a1efad69bdc7fe6f5b (patch)
tree4af90f2225e06ee6269bc3ed894eebcf08992b6b /RELEASING_RAILS.rdoc
parentb12c1b858ea8a781d221e94e2fc22bf729fe2086 (diff)
downloadrails-ec0664a6eb8906fcd31a53a1efad69bdc7fe6f5b.tar.gz
rails-ec0664a6eb8906fcd31a53a1efad69bdc7fe6f5b.tar.bz2
rails-ec0664a6eb8906fcd31a53a1efad69bdc7fe6f5b.zip
Don't symbolize tainted data.
`I18n.locale=` symbolizes its argument, so passing it `params[:locale]` allows one to DOS your application by visiting `...?locale=` URLS repeatedly, with unique values, until the never-GCed symbols monopolize the available memory.
Diffstat (limited to 'RELEASING_RAILS.rdoc')
0 files changed, 0 insertions, 0 deletions