5:33 Play Subscribe with or Intro song by Falseta

Episode #280 - June 12th, 2012

9c5541e591a62dd93a2fd2d45b5732dd.jpg?s=18&r=pg&d=http%3a%2f%2fwww.gravatar.com%2favatar%2f8ebf4339f7c8cd73b53d1d1d3eba7c35 Olivier Lacan 2df14bd29ca441a9d4656f0abae2e0ab.jpg?s=18&r=pg&d=http%3a%2f%2fwww.gravatar.com%2favatar%2f8ebf4339f7c8cd73b53d1d1d3eba7c35 Gregg Pollack

Don't get LeakedIn, secure your routes, use your Savon, catch a Tokaido, put your models in a Display Case, and join the Ruby Study Hall.

Subscribe to our mailing list!

This episode is sponsored by Code School. Learn by doing with our interactive Courses and weekly CodeTV screencasts for just $25/month.

  • Code School
  • Insecure Passwords
  • Rails Security
  • Savon 1.0
  • Tokaido Update
  • Display Case
  • Ruby Study Hall
  • Ruby5

Techniques to Secure your Rails app Jump to Story

Jeremy Walker recently posted part 1 of his three part series talking about techniques to secure your Rails website. He talks about a few ways hackers can manipulate data before it hits your server, how Rails protects us from most of these situations, and thow you can protect yourself further. Data manipulation includes things like session hijacking, session fixation attacks, cross-site request forgery, etc. If you use the “match” keyword without specifying the method within your routes then you can call the route using a get GET method which doesn't check for an authenticity token.

April 18th, 2014

URL parsing with Rippersnapper, awesome APIs with Pliny, thread-safe utilities from Charles Nutter, a revival of the invoicing gem, info about recursion and memoization, querying git with gitql, and refactoring bad controllers all in this episode of the Ruby5 podcast!

April 15th, 2014

In this episode we cover the results of the Cloudflare Heartbleed challenge, tracking trends in the Ruby community with the Ruby Survey, Rails 4.1 ActiveRecord enums, iStats for CPU temperature on OS X and some Insanely Useful ActiveAdmin Customizations.

April 8th, 2014

The internet is heartbleeding plus exciting rails 4.1 features. With special guest Nathan Hessler.

April 8th, 2014

On today's episode: Rails 4 PostgreSQL integration, tips for hiring great software engineers, Ruby Love, what your conference proposal is missing, crafting a conference talk, an introduction to JSON schemas, Build a Ruby Gem, and Surviving APIs with Rails