That you have to use attr_accessible is known throughout the Rails community since "ever". Only toy apps don't use it.
It's like saving passwords in plaintext, only arguably even worse.
That you have to use attr_accessible is known throughout the Rails community since "ever". Only toy apps don't use it.
It's like saving passwords in plaintext, only arguably even worse.
Would you mind sharing any patters you use to DRY up explicit assignment?
@user.public_keys.build(...)
.. where @user is retrieved in a role based manner (that is, you only get the right @user if you are authorized to get it.)Ultimately, this is less an issue of mass assignment specifically and more an overarching one of allowing a user to perform an action in the guise of another. But, of course, these mistakes are commonly made by developers of all skill levels! :-) (me included)
You can do @user.public_keys.find(params[:id]).update_attributes(:user_id => 25)
Its the mass assignment protection on foreign keys that prevents you assigning one of your public keys to someone else, ensuring the chain is correct doesn't necessarily help with this scenario.