Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

Pawel's latest activity

Tuesday, March 15 2011
6552 Rails 3 has_many through forces developer to make *_id attributes unprotected was updated in Ruby on Rails
  • Pawel
    Pawel commented at 12:53 PM

    I was testing this only on 3.0.5.
    From reading the edge source code it appears to be fixed, so the bug could be closed now.

Wednesday, March 09 2011
6552 Rails 3 has_many through forces developer to make *_id attributes unprotected was created in Ruby on Rails
  • Pawel
    Pawel created the ticket at 9:15 PM

    In the classic Group <-> Membership <-> User scenario:

    class Group
      has_many :memberships
      has_many :users, :through => :memberships
    end
    
    class Membership
      ...
Tuesday, March 24 2009
2200 reset_session broken was updated in Ruby on Rails
  • Pawel
    Pawel commented at 11:04 AM

    IMHO reset_session should be simplified to three steps: 1. Clear the session variables. 2. Remove the cookie with session_id. 3. There is no step three ;-)

    When...

Wednesday, March 18 2009
2200 reset_session broken was updated in Ruby on Rails
  • Pawel
    Pawel commented at 4:12 PM

    A workaround to allow your users to log in. Read the comment or don't use it.

    
    class ApplicationController
      # This will destroy session fixation protection ...
  • Pawel
    • Tag set to 2.3.2, activerecord-store, cookie-store, reset_session, session
    • Title changed from session support broken to reset_session broken
    by Pawel at 3:47 PM

    Described problem affects also ActiveRecord session store, but also in development mode.

    def login reset_session session[:user_id] = 5 redirect_to :action => 'l...

2268 rails 2.3 session_options[:id] problem was updated in Ruby on Rails
  • Pawel
    • Tag changed from 2.3, rails, request.session:id, session.session_id to 2.3, rails, request.session_options:id, session.session_id
    by Pawel at 3:08 PM

    This is because of session lazy loading.

    You can work around this by loading the session first and then read its id.

    
    def something
      session[:foo]
      user_c...
Monday, March 09 2009
2177 Unneccessary session loading/creation in form_authenticity_token was created in Ruby on Rails
  • Pawel
    Pawel created the ticket at 11:10 AM

    This is the current implementation of form_authenticity_token:

    
    def form_authenticity_token
      session[:_csrf_token] ||= ActiveSupport::SecureRandom.base64(32...
Sunday, March 08 2009
1528 Only join includes referenced in conditions for count was updated in Ruby on Rails
  • Pawel
    Pawel commented at 11:48 PM

    +1

2174 No way to flush session data to session store immidiately enables race condit... was created in Ruby on Rails
  • Pawel
    Pawel created the ticket at 11:34 PM

    Following code demonstrates race condition in session handling:

    
    def action_that_should_be_called_only_once_per_session
      my_custom_lock_for_current_session ...
2173 Security: reset_session doesn't work under some conditions (session fixation ... was created in Ruby on Rails
  • Pawel
    Pawel created the ticket at 5:32 PM

    Hello,

    As Rails 2.3 is not stable yet I think it won't hurt anyone if I publish this security related bug as a public ticket.

    This bug is similiar to #1601.

    Usi...