Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not Rails-specific that you need to protect your models with reasonable security logic. This particular flavor of "oops, not protected by default" is Rails-specific.

And Rails is highlighting the fact that "allowed by default" is convenient, while the post highlights the fact that "allowed by default" is insecure :-)



"This particular flavor of "oops, not protected by default" is Rails-specific."

Uhh...if it is in most other frameworks, as I claim, and you don't deny, then it is not Rails-specific.


When I say "this particular flavor of", I use that to distinguish between Rails and other frameworks. The protected attribute tags that Rails uses are not common to other frameworks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: