diff options
author | Vijay Dev <vijaydev.cse@gmail.com> | 2012-02-01 22:22:51 +0530 |
---|---|---|
committer | Vijay Dev <vijaydev.cse@gmail.com> | 2012-02-01 22:22:51 +0530 |
commit | e1dbcdcacf62d13914c9e7ec71f0f7319ad32b4a (patch) | |
tree | 73f3ed1cdd7ea8d967deb573f45070352b98f3aa /railties | |
parent | d566fa7721e0fdb46acda282a8d34a4cba8aea3b (diff) | |
download | rails-e1dbcdcacf62d13914c9e7ec71f0f7319ad32b4a.tar.gz rails-e1dbcdcacf62d13914c9e7ec71f0f7319ad32b4a.tar.bz2 rails-e1dbcdcacf62d13914c9e7ec71f0f7319ad32b4a.zip |
fixes the plus sign properly [ci skip]
Diffstat (limited to 'railties')
-rw-r--r-- | railties/guides/source/security.textile | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/railties/guides/source/security.textile b/railties/guides/source/security.textile index 360af6c986..b1a09c0c05 100644 --- a/railties/guides/source/security.textile +++ b/railties/guides/source/security.textile @@ -385,7 +385,7 @@ params[:user] # => {:name => “ow3ned”, :admin => true} So if you create a new user using mass-assignment, it may be too easy to become an administrator. -Note that this vulnerability is not restricted to database columns. Any setter method, unless explicitly protected, is accessible via the <tt>attributes=</tt> method. In fact, this vulnerability is extended even further with the introduction of nested mass assignment (and nested object forms) in Rails 2.3==+==. The +accepts_nested_attributes_for+ declaration provides us the ability to extend mass assignment to model associations (+has_many+, +has_one+, +has_and_belongs_to_many+). For example: +Note that this vulnerability is not restricted to database columns. Any setter method, unless explicitly protected, is accessible via the <tt>attributes=</tt> method. In fact, this vulnerability is extended even further with the introduction of nested mass assignment (and nested object forms) in Rails 2.3<plus>. The +accepts_nested_attributes_for+ declaration provides us the ability to extend mass assignment to model associations (+has_many+, +has_one+, +has_and_belongs_to_many+). For example: <ruby> class Person < ActiveRecord::Base |