Create from params and secure searching
Posted on September 5, 2007 - Filed Under RubyOnRails, Security | 2 Comments
I ran on issue.
I have users created with User.create(params[:form]) and this is secure, in terms of SQL injection. And how I should find user by email using find with :conditions?
Create method does not escape @ sign, but :conditions => ["email = ?", params[:email]]) does escape, so user@domain (inserted to DB by create method) is something [...]
Popularity: 4% [?]
Read More..>>Exception notification - must have for every Rails application
Posted on September 3, 2007 - Filed Under RubyOnRails, run-n-share | Leave a Comment
In every application I’m using excellent plugin called exception notification. Well, almost in every one, since I had forget to include it in Run-N-Share. When my friend have told me about some error he noticed in RNS I have enlightenment moment, and now RNS works with EN plugin.
Exception notification plugin is tool which enables Rails [...]
Popularity: 5% [?]
Read More..>> « go back


