Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

Mathijs Kwik's latest activity

Sunday, January 18 2009
1735 after_save callback should not be called if a before_* callback was cancelled was updated in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik commented at 10:12 AM

    The description of the bug in the changelog is wrong. Look at the code before the patch, it has: "return false if callback(:before_save) == false" in it. So the...

Monday, November 03 2008
1145 Bug: InvalidAuthenticityToken incorrectly raised for XML controller#destroy r... was updated in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik commented at 12:22 AM

    @Alex

    Ok, but 'that domain' would happen to be the rails-site right? so an attacker can't set that. In case I want to enable it for my site, I should already ma...

Sunday, November 02 2008
1145 Bug: InvalidAuthenticityToken incorrectly raised for XML controller#destroy r... was updated in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik commented at 7:10 PM

    Flash can forge every kind of request they want, but as far as I know (don't have any reference, and I don't know flash, so I must have picked it up somewhere) ...

Friday, October 31 2008
1145 Bug: InvalidAuthenticityToken incorrectly raised for XML controller#destroy r... was updated in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik commented at 8:40 AM

    Interesting question, I can't answer that.

    For example, this existing test is no longer valid if we're only going to worry about non-ajax html forms:

    I think ...

Wednesday, October 29 2008
1145 Bug: InvalidAuthenticityToken incorrectly raised for XML controller#destroy r... was updated in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik commented at 5:52 AM

    Well, you are right, checking for an empty content format + DELETE + request format XML is the thing that needs to get fixed now.

    But looking at the problem fro...

Wednesday, October 01 2008
73 SECURITY BUG - Request Forgery protection checks for 'Accept' header instead ... was updated in Ruby on Rails
1145 Bug: InvalidAuthenticityToken incorrectly raised for XML controller#destroy r... was updated in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik commented at 7:06 AM

    Matthew,

    Please read the thread you linked to entirely (especially my may-1st post).

    The reason why we changed to content-type instead of accept-header is simpl...

Monday, September 08 2008
992 sql variable substitution on :joins was created in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik created the ticket at 12:28 AM

    I would like to have substitution+sanitizing features on :joins.

    
    class Post
      belongs_to :user
      named_scope :by_admins, {
        :joins => 'inner join users as...
991 find_or_initialize_by does not add initialized records to associationproxy was created in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik created the ticket at 12:01 AM

    When using find_or_initialize_by on an association, newly created objects don't get added to the association-array. This is the case when using build on an asso...

Sunday, September 07 2008
990 association#build inconsistency was created in Ruby on Rails
  • Mathijs Kwik
    Mathijs Kwik created the ticket at 11:22 PM

    When building an object through an association, the resulting object isn't bound to the proxy owner if the proxy owner is a new record. If the proxy owner is al...