Require explict allowlisting of attributes and associations#1400
Require explict allowlisting of attributes and associations#1400deivid-rodriguez merged 1 commit intomainfrom
Conversation
742c863 to
8674980
Compare
|
@scarroll32 Ok with releasing this as Ransack 4.0? |
lukas-eu
left a comment
There was a problem hiding this comment.
A typo and another idea for naming the list of all attributes/associations
22be99f to
81f1d25
Compare
Co-authored-by: lukas-eu <[email protected]> Co-authored-by: Wes Oldenbeuving <[email protected]>
81f1d25 to
05db5c6
Compare
|
I will prepare a release tomorrow. |
|
@scarroll32 I created a release draft. It's been a while without releases, so let me know how it looks if you have some time! Otherwise I'll just release this tommorrow™️. |
|
I really understood the security idea about this change. But when something doesn't have a door the path is "free". However, when all of the world need to use this door, you generate a big problem! Imagine, need to generate a key for everyone. So, this behavior break so many applications that discourages people use ransack. Because the core changed and break the whole app, forced to implement this security feature. |
Fixes #1273.