diff options
author | Doug Cole <doug@estately.com> | 2013-10-26 19:22:31 -0700 |
---|---|---|
committer | Doug Cole <doug@estately.com> | 2013-10-26 19:22:31 -0700 |
commit | 7171111d3af10c80e3b38658d4fa0aa36858677f (patch) | |
tree | 13c78f5977c6a8cd39c930638f138f11afde6dee /actionpack/lib | |
parent | 52199d1fd41ffc439357c16a7873fb04444175cd (diff) | |
download | rails-7171111d3af10c80e3b38658d4fa0aa36858677f.tar.gz rails-7171111d3af10c80e3b38658d4fa0aa36858677f.tar.bz2 rails-7171111d3af10c80e3b38658d4fa0aa36858677f.zip |
don't mutate hash with fetch
Diffstat (limited to 'actionpack/lib')
-rw-r--r-- | actionpack/lib/action_controller/metal/strong_parameters.rb | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/actionpack/lib/action_controller/metal/strong_parameters.rb b/actionpack/lib/action_controller/metal/strong_parameters.rb index 66403d533c..fcc76f6225 100644 --- a/actionpack/lib/action_controller/metal/strong_parameters.rb +++ b/actionpack/lib/action_controller/metal/strong_parameters.rb @@ -284,7 +284,14 @@ module ActionController # params.fetch(:none, 'Francesco') # => "Francesco" # params.fetch(:none) { 'Francesco' } # => "Francesco" def fetch(key, *args) - convert_hashes_to_parameters(key, super) + value = super + # Don't rely on +convert_hashes_to_parameters+ + # so as to not mutate via a +fetch+ + if value.is_a?(Hash) + value = self.class.new(value) + value.permit! if permitted? + end + value rescue KeyError raise ActionController::ParameterMissing.new(key) end |