Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Protect against error when parsing parameters with Bad Request | Rafael Mendonça França | 2014-08-19 | 1 | -2/+2 |
| | | | | Related with #11795. | ||||
* | Merge pull request #16299 from sikachu/ps-safer-ac-params | Jeremy Kemper | 2014-08-19 | 1 | -3/+84 |
|\ | | | | | Update `ActionController::Parameters` to be more secure on parameters handling | ||||
| * | User `#to_hash` instead of calling `super` | Prem Sichanugrist | 2014-08-18 | 1 | -1/+1 |
| | | | | | | | | Ruby 1.9.3 does not implement Hash#to_h, so we can't call `super` on it. | ||||
| * | Fix failing test on several methods on Parameter | Prem Sichanugrist | 2014-08-18 | 1 | -1/+25 |
| | | | | | | | | | | | | | | * `each` * `each_pair` * `delete` * `select!` | ||||
| * | Refactor code to reduce duplicate `self.class.new` | Prem Sichanugrist | 2014-08-18 | 1 | -12/+10 |
| | | |||||
| * | Add missing `Hash` methods to `AC::Parameters` | Prem Sichanugrist | 2014-08-18 | 1 | -0/+40 |
| | | | | | | | | | | | | | | | | | | | | | | | | This is to make sure that `permitted` status is maintained on the resulting object. I found these methods that needs to be redefined by looking for `self.class.new` in the code. * extract! * transform_keys * transform_values | ||||
| * | Make `AC::Params#to_h` return Hash with safe keys | Prem Sichanugrist | 2014-08-18 | 1 | -0/+19 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `ActionController::Parameters#to_h` now returns a `Hash` with unpermitted keys removed. This change is to reflect on a security concern where some method performed on an `ActionController::Parameters` may yield a `Hash` object which does not maintain `permitted?` status. If you would like to get a `Hash` with all the keys intact, duplicate and mark it as permitted before calling `#to_h`. params = ActionController::Parameters.new(name: 'Senjougahara Hitagi') params.to_h # => {} unsafe_params = params.dup.permit! unsafe_params.to_h # => {"name"=>"Senjougahara Hitagi"} safe_params = params.permit(:name) safe_params.to_h # => {"name"=>"Senjougahara Hitagi"} This change is consider a stopgap as we cannot chage the code to stop `ActionController::Parameters` to inherit from `HashWithIndifferentAccess` in the next minor release. Also, adding a CHANGELOG entry to mention that `ActionController::Parameters` will not inheriting from `HashWithIndifferentAccess` in the next major version. | ||||
* | | Merge branch 'master' of github.com:rails/docrails | Vijay Dev | 2014-08-19 | 3 | -2/+31 |
|\ \ | | | | | | | | | | | | | | | | | | | Conflicts: actionpack/lib/action_controller/metal/mime_responds.rb actionview/lib/action_view/vendor/html-scanner/html/sanitizer.rb activerecord/lib/active_record/type/value.rb | ||||
| * | | Uppercase HTML in docs. | Hendy Tanata | 2014-08-08 | 3 | -10/+10 |
| | | | | | | | | | | | | [skip ci] | ||||
| * | | [ci skip] Document ActionDispatch::Static | schneems | 2014-08-05 | 1 | -0/+9 |
| | | | |||||
| * | | [ci skip] document ActionDispatch::FileHandler | schneems | 2014-08-05 | 1 | -0/+10 |
| | | | |||||
| * | | [ci skip] Document PublicExceptions middleware | schneems | 2014-08-05 | 1 | -0/+10 |
| | | | |||||
* | | | Add missing require | Godfrey Chan | 2014-08-18 | 1 | -0/+2 |
| |/ |/| | |||||
* | | Deprecate TagAssertion instead of removing | Rafael Mendonça França | 2014-08-18 | 1 | -0/+1 |
| | | |||||
* | | Merge pull request #15889 from carnesmedia/model-name | Rafael Mendonça França | 2014-08-17 | 2 | -6/+6 |
|\ \ | | | | | | | | | | Use #model_name on instances instead of classes | ||||
| * | | Use #model_name on instances instead of classes | Amiel Martin | 2014-06-24 | 2 | -6/+6 |
| | | | | | | | | | | | | | | | | | | This allows rails code to be more confdent when asking for a model name, instead of having to ask for the class. Rails core discussion here: https://groups.google.com/forum/#!topic/rubyonrails-core/ThSaXw9y1F8 | ||||
* | | | Merge branch 'loofah' | Rafael Mendonça França | 2014-08-17 | 6 | -597/+27 |
|\ \ \ | | | | | | | | | | | | | | | | | Conflicts: Gemfile | ||||
| * \ \ | Merge branch 'master' into loofah | Rafael Mendonça França | 2014-08-17 | 13 | -607/+218 |
| |\ \ \ | | | | | | | | | | | | | | | | | | | | | Conflicts: actionpack/CHANGELOG.md | ||||
| * \ \ \ | Merge branch 'master' into loofah | Rafael Mendonça França | 2014-08-12 | 36 | -402/+512 |
| |\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: actionpack/CHANGELOG.md actionpack/test/controller/integration_test.rb actionview/CHANGELOG.md | ||||
| * | | | | | We don't need loofah for the assertions | Rafael Mendonça França | 2014-07-15 | 2 | -4/+2 |
| | | | | | | | | | | | | | | | | | | | | | | | | We can just use nokogiri | ||||
| * | | | | | Merge pull request #11218 from kaspth/loofah-integration | Rafael Mendonça França | 2014-07-10 | 6 | -597/+29 |
| |\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Loofah-integration Conflicts: actionpack/CHANGELOG.md actionview/CHANGELOG.md | ||||
| | * | | | | | Add document_root_element to ActionDispatch::IntegrationTest so ↵ | Timm | 2014-06-16 | 1 | -0/+4 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | assert_select can be called without specifying a root. | ||||
| | * | | | | | Moved html_document to ActionDispatch::Assertions. Included the ↵ | Timm | 2014-06-16 | 2 | -7/+13 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Rails::Dom::Testing::Assertions there as well. | ||||
| | * | | | | | Support for changes in SelectorAssertions. | Timm | 2014-06-16 | 1 | -0/+14 |
| | | | | | | | |||||
| | * | | | | | Changed deprecation message in dom and selector assertions in Action Dispatch. | Timm | 2014-06-16 | 2 | -2/+2 |
| | | | | | | | |||||
| | * | | | | | Removed tag.rb, since it is actually removed, not just deprecated. [ci skip] | Timm | 2014-06-16 | 1 | -3/+0 |
| | | | | | | | |||||
| | * | | | | | Moved ActionView::Assertions dependency from Action Pack's lib to ↵ | Timm | 2014-06-16 | 2 | -4/+1 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | abstract_unit.rb. | ||||
| | * | | | | | Added deprecation warning to ActionDispatch::Assertions::TagAssertions. | Timm | 2014-06-16 | 1 | -0/+3 |
| | | | | | | | |||||
| | * | | | | | Trimmed deprecation message for ActionDispatch::Assertions::SelectorAssertions. | Timm | 2014-06-16 | 1 | -1/+1 |
| | | | | | | | |||||
| | * | | | | | Require ActionView::Assertions in ActionController test_case.rb. | Timm | 2014-06-16 | 1 | -0/+1 |
| | | | | | | | |||||
| | * | | | | | Moved Dom and Selector assertions from ActionDispatch to ActionView. | Timm | 2014-06-16 | 5 | -544/+7 |
| | | | | | | | |||||
| | * | | | | | Fixed: assert_select_encoded finds the right content. No longer uses a ↵ | Timm | 2014-06-16 | 1 | -5/+9 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | <encoded> wrapper. Updated tests to reflect this. | ||||
| | * | | | | | Removed mention of css_select supporting substitution values. It is not ↵ | Timm | 2014-06-16 | 1 | -7/+1 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | tested anywhere. | ||||
| | * | | | | | Updated documentation to state more things about css selectors with ↵ | Timm | 2014-06-16 | 1 | -3/+11 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | substitution values. | ||||
| | * | | | | | Reworked the wrapping root in NodeSet implementation in css_select. | Timm | 2014-06-16 | 1 | -3/+5 |
| | | | | | | | |||||
| | * | | | | | Wrapped element to search in NodeSet. Changed selectors to selector. | Timm | 2014-06-16 | 1 | -3/+5 |
| | | | | | | | |||||
| | * | | | | | Moved around alias line. | Timm | 2014-06-16 | 1 | -2/+2 |
| | | | | | | | |||||
| | * | | | | | Returning from filter if matches are empty. | Timm | 2014-06-16 | 1 | -1/+1 |
| | | | | | | | |||||
| | * | | | | | Fixed: no longer wrapped @selected in fragment, since .css works fine ↵ | Timm | 2014-06-16 | 1 | -2/+1 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | without it. | ||||
| | * | | | | | Reverted to using documents instead of document fragments, since searching ↵ | Timm | 2014-06-16 | 1 | -3/+6 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | via default xml namespaces didn't work. | ||||
| | * | | | | | add_regex returns inspected value for non Regexp objects. Workaround, so ↵ | Timm | 2014-06-16 | 1 | -1/+2 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | users don't have to care about enclosing values in double quotes. | ||||
| | * | | | | | Fixed: inadvertently called message method in MiniTest instead of ↵ | Timm | 2014-06-16 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | selector.message. | ||||
| | * | | | | | Cleaned up SubstitutionContext class. | Timm | 2014-06-16 | 1 | -10/+8 |
| | | | | | | | |||||
| | * | | | | | Simplified assert_select further by moving match filtering into HTMLSelector ↵ | Timm | 2014-06-16 | 1 | -32/+29 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | select. | ||||
| | * | | | | | Fixed: now only compares html of children in filter_matches. | Timm | 2014-06-16 | 1 | -1/+1 |
| | | | | | | | |||||
| | * | | | | | Added NodeSet comparison to possible root element in determine_root_from. | Timm | 2014-06-16 | 1 | -1/+1 |
| | | | | | | | |||||
| | * | | | | | Changed html_document to use fragments. Changed response_from_page to be an ↵ | Timm | 2014-06-16 | 1 | -6/+3 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | alias of html_document. | ||||
| | * | | | | | Fixed bug by switching to Loofah fragment instead of document. | Timm | 2014-06-16 | 1 | -2/+2 |
| | | | | | | | |||||
| | * | | | | | Changed css_select to not count on multiple selectors. Fixed bug in ↵ | Timm | 2014-06-16 | 1 | -8/+10 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | determine_root_from where @selected was an Array. Changed assert_select_encoded to use a fragment instead of a document. | ||||
| | * | | | | | Added a proper substitution context class. Changed ArgumentFilter to be a ↵ | Timm | 2014-06-16 | 1 | -34/+47 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | selector. It is now called HTMLSelector. |