This project is archived and is in readonly mode.
deprecate attr_accessible, attr_protected
-
Michael Koziarski
- State changed from new to wontfix
While there are several cases where a more complicated mass assignment permissions model is needed, the base case is incredibly useful for a huge number of users.
Requiring everyone to specify every attribute every time they assign them sits well on the other side of the 'reasonable complexity' line.
-
cainlevy
True. The base case does cover a lot of ground. And until I finally did away with ActiveScaffold (the beast) and went back to a more light-weight admin interface approach (http://github.com/cainlevy/presenting), it was enough for me.
I suspect, though, that moving the assignable attribute list from the model to the controller would be a nearly net zero change in terms of complexity, except where the complexity is useful.
Thanks to these lovely RESTful resource controllers, my application rarely mass assigns to some model class in more than one location. And when it does, it's nearly always because it's a different permissions context. So in the former case I'd remove a line of code from my User model and add it to my UsersController ... no more or less complex. And the latter case is, well, exactly where I'd want to specify the assignable columns in the controller anyway!
Hopefully I'm not committing the fallacy of assuming everyone's application works like mine.
