Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Filtering parameters inside arrays when logging

#2851

I've stumbled upon this issue while creating an application which makes use of nested forms. Basically, I have an Account model which has many Users. When I create the account it also creates one User. The action receives parameters like:

:account => { :name => 'foo', :users_attributes => [{ :login => 'foo', :password => 'secret', :password_confirmation => 'secret' }] }

Since my controller has the following line:

filter_parameter_logging :password, :password_confirmation

I was expecting to see both password and password_confirmation filtered, but they weren't. Looking inside filter_parameter_logging I understand that it didn't treated arrays at all. I've made a patch, but it seems rails.lighthouseapp.com is down, so I'll just post it here. The patch contains changes to both code and tests. I've made it by branching origin/2-3-stable.

I think it may be wrong in older versions of rails too.

Reported by vicente.mundim (at gmail) · June 29th, 2009 @ 01:54 PM

State: resolved
Milestone: 2.x
Assigned to: nobody
Importance: none

Activity

  1. vicente.mundim (at gmail)
    vicente.mundim (at gmail)
    • Tag changed from action_controller, logging to action_controller, logging, patch

    June 29th, 2009 @ 01:55 PM

  2. Yehuda Katz (wycats)
    Yehuda Katz (wycats)
    • State changed from new to resolved

    It appears that this has been resolved with the following commit:

    http://github.com/rails/rails/commit/9407f6e9a428b37517fdd779eac15e...

    July 2nd, 2009 @ 12:16 AM

  3. Will Bryant
    Will Bryant

    Was it intended that this results in filter_parameters being called with scalar arguments, for example when you use:

    post :create, :foo => ["bar", "baz"]

    filter_parameters gets called with "bar" and then with "baz". This works (though fixnums don't, which broke my specs - but think that wouldn't occur in real use), but that seems quite accidental to me (it relies on String#collect returning an array with the string in it).

    July 6th, 2009 @ 04:00 AM

  4. Alexey I. Froloff
    Alexey I. Froloff

    I second this. It dies with NoMethodError when parameters contains something like :role_ids => [1, 2, 3] or :foo => ["bar", "baz"]. This scheme used by redmine for example.

    July 28th, 2009 @ 07:22 PM

  5. gmackerron
    gmackerron

    And I third it, strongly. This change just broke a production app of mine on Ruby 1.9, because on 1.9 there is no String#collect method!

    July 30th, 2009 @ 12:38 PM

  6. Yehuda Katz (wycats)
    Yehuda Katz (wycats)

    What are people seconding and thirding exactly?

    July 30th, 2009 @ 05:32 PM

  7. gmackerron
    gmackerron

    Will Bryant's suspicion that the results of the fix are not fully what was intended, since filter_parameters gets called with individual string arguments, and this causes 500 errors on 1.9.

    July 30th, 2009 @ 05:40 PM

  8. vicente.mundim (at gmail)
  9. gmackerron
    gmackerron

    Good news -- thanks for pointing this out.

    August 1st, 2009 @ 02:04 PM