If an app makes it possible to do SQL injections, whose fault is it?
What Rails have done is to have a particular default (whose correctness can be debated) and document how it can be exploited and how to safeguard from it.
What Rails have done is to have a particular default (whose correctness can be debated) and document how it can be exploited and how to safeguard from it.