5:27 Play Subscribe with or Intro song by Falseta

Episode #252 - March 6th, 2012

2df14bd29ca441a9d4656f0abae2e0ab.jpg?s=18&r=pg&d=http%3a%2f%2fwww.gravatar.com%2favatar%2f8ebf4339f7c8cd73b53d1d1d3eba7c35 Gregg Pollack 0d2bf6fbf141a1995560fa9273992ff0.jpg?s=18&r=pg&d=http%3a%2f%2fwww.gravatar.com%2favatar%2f8ebf4339f7c8cd73b53d1d1d3eba7c35 Nathaniel Bibler

We start out this episode talking about the Github Rails drama from this weekend along with Yehuda's suggestion to fix the issue, MethodProfiler, Ariane, SimpleForm 2.0, and Versionist.

Subscribe to our mailing list!

This episode is sponsored by Top Ruby Jobs. Everyone deserves to love their job (and it's probably in Ruby).

  • Top Ruby Jobs
  • Github Issue
  • Rails Response
  • Yehuda's Suggestion
  • MethodProfiler
  • Ariane
  • SimpleForm 2.0
  • Versionist
  • Ruby5

Yehuda’s Mass Assignment Approach Jump to Story

Also in response to this Yehuda Katz gave two suggestions on how to combat this issue. One was to create a signed token when using form_for that contains the fields present in the form. The second layer solution was to move method whitelisting into the controllers, so you could set attribute access based on the context.

December 19, 2014

Eastward Ho, Git ours/theirs and where does your code go?

December 16, 2014

This week we have Streem, Rails 4.2.rc3, Papercrop, and RubyMotion 3.0.

December 9, 2014

This week we have a jRuby security release, a new Command API for ROM, Traveling Ruby, early validations, easy rewrites with Ruby and Science!, and a Rails Camp not too far from Hobbiton.

December 5th, 2014

RubyConf 2014 on Confreaks, browser geolocation with Spyme, referential integrity with foreign keys, forwarding messages with tell, and free SecCasts all in this episode of the Ruby5.