We are now explicitly whitelisting all parameters for Post creation. A nice side-effect is that it cleans up the #create action in PostsController. We can now trust that all parameters entering PostCreator are of a safe scalar type. |
||
|---|---|---|
| .. | ||
| components | ||
| controllers | ||
| helpers | ||
| mixins | ||
| models | ||
| routes | ||
| templates | ||
| views | ||