This project is archived and is in readonly mode.
accepts_nested_attributes_for
-
23inhouse
There is a typo please use:
rake test:functionals
-
Santiago Pastorino
- Importance changed from to Low
Have you tried tests in 3.0.3? even better what's about 3.0.4.rc1?.
Thanks. -
23inhouse
I should have mentioned that it doesn't work in any version after 3.0.0. I was trying to isolate the change that broke it.
I just ran it in 3.0.4.rc1 and it still fails to pass the test.
P.S. I'm using ruby-1.9.2-p0
-
Santiago Pastorino
Hey sorry I hadn't check the issue deeply in my first glance.
The issue you're pointing, is not a real one :), is a security fix. -
Michael Koziarski
- State changed from new to invalid
Your application was relying on a security vulnerability that was fixed in 3.0.1
http://groups.google.com/group/rubyonrails-security/t/f9f913d328dafe0c
If we let you specify the ID like that you could edit arbitrary records in the database by simply changing a few form parameters. This will never be fixed.
-
23inhouse
Michael and Santiago
Thank you for clarifying that. I was really enjoying just jamming the params into the Models attributes= methods and having it all work, but i can see the problem this causes.
Thanks again.
Ben