aboutsummaryrefslogtreecommitdiffstats
path: root/activerecord/lib/active_record/associations/association.rb
diff options
context:
space:
mode:
authorRafael Mendonça França <rafaelmfranca@gmail.com>2012-11-22 06:47:44 -0800
committerRafael Mendonça França <rafaelmfranca@gmail.com>2012-11-22 06:47:44 -0800
commit83e71051258b98bd5c4df80b321c7b690ddcab35 (patch)
treec40be8c2333aaba0928e41407e0fd2ac0442809c /activerecord/lib/active_record/associations/association.rb
parent4e00e8e91637e117f702ec277a5db1fd087cb347 (diff)
parentd397a38c0268e61295e23f617e9bf70d905ea610 (diff)
downloadrails-83e71051258b98bd5c4df80b321c7b690ddcab35.tar.gz
rails-83e71051258b98bd5c4df80b321c7b690ddcab35.tar.bz2
rails-83e71051258b98bd5c4df80b321c7b690ddcab35.zip
Merge pull request #8295 from senny/8265_backport
backport #8291, prevent mass assignment of polymorphic type with `build`
Diffstat (limited to 'activerecord/lib/active_record/associations/association.rb')
-rw-r--r--activerecord/lib/active_record/associations/association.rb3
1 files changed, 2 insertions, 1 deletions
diff --git a/activerecord/lib/active_record/associations/association.rb b/activerecord/lib/active_record/associations/association.rb
index 59c1bad559..ab0d888b16 100644
--- a/activerecord/lib/active_record/associations/association.rb
+++ b/activerecord/lib/active_record/associations/association.rb
@@ -231,7 +231,8 @@ module ActiveRecord
def build_record(attributes, options)
reflection.build_association(attributes, options) do |record|
- attributes = create_scope.except(*(record.changed - [reflection.foreign_key]))
+ skip_assign = [reflection.foreign_key, reflection.type].compact
+ attributes = create_scope.except(*(record.changed - skip_assign))
record.assign_attributes(attributes, :without_protection => true)
end
end