colindean / plas

Pittco LAN Administration System
http://pittco.org
Other
14 stars 4 forks source link

Add attr_accessible to models where necessary #68

Closed colindean closed 12 years ago

colindean commented 12 years ago

Following the recent github.com attack, I realized that plas is vulnerable to this. Time to fix it!

colindean commented 12 years ago

mass-assignment vulnerability

colindean commented 12 years ago

Models that have a TODO or have nothing there are likely to be rewritten soon anyway.