06 March 2012 12:00
Issue #5228: Mass assignment vulnerability - how to force dev. define attr_accesible? · rails/rails · GitHub
by night.kameDrPizza commented 2 days ago
Dear Rails people,
Have you learned nothing?
"Insecure-by-default" means "insecure". Trusting the programmer to fix things up and make them secure has never worked.
You guys have reinvented strcpy(). Way to go.
1
(1 marks)