This project is archived and is in readonly mode.
:attr_accessible nil breaks AR session store
-
josh
- Milestone cleared.
-
josh
- State changed from new to wontfix
I'm not sure this is a good idea in general. If you add ActiveRecord::Base.send(:attr_accessible, nil) to base no AR attributes will be able to be saved on any model.
I would think the same issue would have existed in any version of Rails.
-
Peter Nash
The reason for adding ActiveRecord::Base.send(:attr_accessible, nil) is so that the default behaviour of all application model classes is to NOT allow updates to to attributes from params unless access is specifically allowed with :attr_accessible in each model. This way it relies on the programmer to explicitly declare which attributes can be updated from parameter hashes. I know that there are varying opinions about whether that's a good thing to enforce but in the past setting this did not break any of the core Rails classes. For background on why I prefer to "whitelist" attr_accessible see http://railscasts.com/episodes/26
-
Peter Nash
I meant to add that using ActiveRecord::Base.send(:attr_accessible, nil) to enforce the use of attr_accessible in models used to work fine in 2.1, 2.2 and 2.3RC1 - it's only on Edge that it breaks AR sessions. However, if anyone else is affected by this, an alternative strategy of auditing for the use of attr_accessible in models instead of enforcing it is detailed here http://blog.insoshi.com/2008/09/...
-
keith_shetler (at hotmail)
This appears in 2.3.2. The work-around:
ActiveRecord::Base.send(:attr_accessible, nil)
ActiveRecord::Base.send(:attr_accessible, :session_id)This correctly allows they system to set the :session_id attribute.