Fix mass assignment vuln to tag alias/implication status (2704).

This commit is contained in:
evazion
2016-10-11 07:58:08 +00:00
parent 789dede893
commit 7e3284c87f
4 changed files with 18 additions and 4 deletions

View File

@@ -15,7 +15,7 @@ class TagAliasesController < ApplicationController
@tag_alias = TagAlias.find(params[:id])
if @tag_alias.is_pending? && @tag_alias.editable_by?(CurrentUser.user)
@tag_alias.update_attributes(params[:tag_alias])
@tag_alias.update_attributes(update_params)
end
respond_with(@tag_alias)
@@ -46,4 +46,10 @@ class TagAliasesController < ApplicationController
@tag_alias.approve!(CurrentUser.user.id)
respond_with(@tag_alias, :location => tag_alias_path(@tag_alias))
end
private
def update_params
params.require(:tag_alias).permit(:antecedent_name, :consequent_name, :forum_topic_id)
end
end

View File

@@ -15,7 +15,7 @@ class TagImplicationsController < ApplicationController
@tag_implication = TagImplication.find(params[:id])
if @tag_implication.is_pending? && @tag_implication.editable_by?(CurrentUser.user)
@tag_implication.update_attributes(params[:tag_implication])
@tag_implication.update_attributes(update_params)
end
respond_with(@tag_implication)
@@ -51,4 +51,10 @@ class TagImplicationsController < ApplicationController
@tag_implication.approve!(CurrentUser.user.id)
respond_with(@tag_implication, :location => tag_implication_path(@tag_implication))
end
private
def update_params
params.require(:tag_implication).permit(:antecedent_name, :consequent_name, :forum_topic_id)
end
end