Closed jpaas closed 8 years ago
I'm using resque-web 0.0.8 with Rails 5.0.0.rc1. Everything seems to work ok except the failures page which results in this error:
ActionView::Template::Error (Attempting to generate a URL from non-sanitized request parameters! An attacker can inject malicious data into the generated URL, such as changing the host. Whitelist and sanitize passed parameters to be secure.): 28: <% end %> 29: </ul> 30: 31: <%= pagination(start: failure_start_at, total: failure_size) unless params[:class] %> 32: <% end %> actionpack (5.0.0.rc1) lib/action_dispatch/routing/url_for.rb:176:in `url_for' actionview (5.0.0.rc1) lib/action_view/routing_url_for.rb:96:in `url_for' actionview (5.0.0.rc1) lib/action_view/helpers/url_helper.rb:196:in `link_to' resque-web (0.0.8) app/helpers/resque_web/application_helper.rb:54:in `pagination' resque-web (0.0.8) app/views/resque_web/failures/index.html.erb:31:in `___sers_jpaas__rvm_gems_ruby_______karma_gems_resque_web_______app_views_resque_web_failures_index_html_erb__510230725911668492_70343140603500' actionview (5.0.0.rc1) lib/action_view/template.rb:158:in `block in render' activesupport (5.0.0.rc1) lib/active_support/notifications.rb:166:in `instrument' actionview (5.0.0.rc1) lib/action_view/template.rb:348:in `instrument' actionview (5.0.0.rc1) lib/action_view/template.rb:156:in `render' actionview (5.0.0.rc1) lib/action_view/renderer/template_renderer.rb:54:in `block (2 levels) in render_template' actionview (5.0.0.rc1) lib/action_view/renderer/abstract_renderer.rb:42:in `block in instrument' activesupport (5.0.0.rc1) lib/active_support/notifications.rb:164:in `block in instrument' activesupport (5.0.0.rc1) lib/active_support/notifications/instrumenter.rb:21:in `instrument' activesupport (5.0.0.rc1) lib/active_support/notifications.rb:164:in `instrument' actionview (5.0.0.rc1) lib/action_view/renderer/abstract_renderer.rb:41:in `instrument' actionview (5.0.0.rc1) lib/action_view/renderer/template_renderer.rb:53:in `block in render_template' actionview (5.0.0.rc1) lib/action_view/renderer/template_renderer.rb:61:in `render_with_layout' actionview (5.0.0.rc1) lib/action_view/renderer/template_renderer.rb:52:in `render_template' actionview (5.0.0.rc1) lib/action_view/renderer/template_renderer.rb:14:in `render' actionview (5.0.0.rc1) lib/action_view/renderer/renderer.rb:42:in `render_template' actionview (5.0.0.rc1) lib/action_view/renderer/renderer.rb:23:in `render' actionview (5.0.0.rc1) lib/action_view/rendering.rb:103:in `_render_template' actionpack (5.0.0.rc1) lib/action_controller/metal/streaming.rb:217:in `_render_template' actionview (5.0.0.rc1) lib/action_view/rendering.rb:83:in `render_to_body' actionpack (5.0.0.rc1) lib/action_controller/metal/rendering.rb:52:in `render_to_body' actionpack (5.0.0.rc1) lib/action_controller/metal/renderers.rb:144:in `render_to_body' actionpack (5.0.0.rc1) lib/abstract_controller/rendering.rb:26:in `render' actionpack (5.0.0.rc1) lib/action_controller/metal/rendering.rb:36:in `render' actionpack (5.0.0.rc1) lib/action_controller/metal/instrumentation.rb:44:in `block (2 levels) in render' activesupport (5.0.0.rc1) lib/active_support/core_ext/benchmark.rb:12:in `block in ms' /Users/jpaas/.rvm/rubies/ruby-2.3.1/lib/ruby/2.3.0/benchmark.rb:308:in `realtime' activesupport (5.0.0.rc1) lib/active_support/core_ext/benchmark.rb:12:in `ms' actionpack (5.0.0.rc1) lib/action_controller/metal/instrumentation.rb:44:in `block in render' actionpack (5.0.0.rc1) lib/action_controller/metal/instrumentation.rb:87:in `cleanup_view_runtime' activerecord (5.0.0.rc1) lib/active_record/railties/controller_runtime.rb:25:in `cleanup_view_runtime' actionpack (5.0.0.rc1) lib/action_controller/metal/instrumentation.rb:43:in `render' actionpack (5.0.0.rc1) lib/action_controller/metal/implicit_render.rb:36:in `default_render' actionpack (5.0.0.rc1) lib/action_controller/metal/basic_implicit_render.rb:4:in `block in send_action' actionpack (5.0.0.rc1) lib/action_controller/metal/basic_implicit_render.rb:4:in `tap' actionpack (5.0.0.rc1) lib/action_controller/metal/basic_implicit_render.rb:4:in `send_action' actionpack (5.0.0.rc1) lib/abstract_controller/base.rb:181:in `process_action' actionpack (5.0.0.rc1) lib/action_controller/metal/rendering.rb:30:in `process_action' actionpack (5.0.0.rc1) lib/abstract_controller/callbacks.rb:20:in `block in process_action' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:126:in `call' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:506:in `block (2 levels) in compile' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:455:in `call' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:101:in `__run_callbacks__' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:750:in `_run_process_action_callbacks' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:90:in `run_callbacks' actionpack (5.0.0.rc1) lib/abstract_controller/callbacks.rb:19:in `process_action' actionpack (5.0.0.rc1) lib/action_controller/metal/rescue.rb:31:in `process_action' actionpack (5.0.0.rc1) lib/action_controller/metal/instrumentation.rb:32:in `block in process_action' activesupport (5.0.0.rc1) lib/active_support/notifications.rb:164:in `block in instrument' activesupport (5.0.0.rc1) lib/active_support/notifications/instrumenter.rb:21:in `instrument' activesupport (5.0.0.rc1) lib/active_support/notifications.rb:164:in `instrument' actionpack (5.0.0.rc1) lib/action_controller/metal/instrumentation.rb:30:in `process_action' actionpack (5.0.0.rc1) lib/action_controller/metal/params_wrapper.rb:248:in `process_action' activerecord (5.0.0.rc1) lib/active_record/railties/controller_runtime.rb:18:in `process_action' actionpack (5.0.0.rc1) lib/abstract_controller/base.rb:126:in `process' actionview (5.0.0.rc1) lib/action_view/rendering.rb:30:in `process' actionpack (5.0.0.rc1) lib/action_controller/metal.rb:190:in `dispatch' actionpack (5.0.0.rc1) lib/action_controller/metal.rb:262:in `dispatch' actionpack (5.0.0.rc1) lib/action_dispatch/routing/route_set.rb:50:in `dispatch' actionpack (5.0.0.rc1) lib/action_dispatch/routing/route_set.rb:32:in `serve' actionpack (5.0.0.rc1) lib/action_dispatch/journey/router.rb:39:in `block in serve' actionpack (5.0.0.rc1) lib/action_dispatch/journey/router.rb:26:in `each' actionpack (5.0.0.rc1) lib/action_dispatch/journey/router.rb:26:in `serve' actionpack (5.0.0.rc1) lib/action_dispatch/routing/route_set.rb:725:in `call' railties (5.0.0.rc1) lib/rails/engine.rb:522:in `call' railties (5.0.0.rc1) lib/rails/railtie.rb:193:in `public_send' railties (5.0.0.rc1) lib/rails/railtie.rb:193:in `method_missing' actionpack (5.0.0.rc1) lib/action_dispatch/routing/mapper.rb:17:in `block in <class:Constraints>' actionpack (5.0.0.rc1) lib/action_dispatch/routing/mapper.rb:46:in `serve' actionpack (5.0.0.rc1) lib/action_dispatch/journey/router.rb:39:in `block in serve' actionpack (5.0.0.rc1) lib/action_dispatch/journey/router.rb:26:in `each' actionpack (5.0.0.rc1) lib/action_dispatch/journey/router.rb:26:in `serve' actionpack (5.0.0.rc1) lib/action_dispatch/routing/route_set.rb:725:in `call' actionview (5.0.0.rc1) lib/action_view/digestor.rb:12:in `call' http_accept_language (2.0.5) lib/http_accept_language/middleware.rb:14:in `call' rack (2.0.0.rc1) lib/rack/etag.rb:25:in `call' rack (2.0.0.rc1) lib/rack/conditional_get.rb:25:in `call' rack (2.0.0.rc1) lib/rack/head.rb:12:in `call' rack (2.0.0.rc1) lib/rack/session/abstract/id.rb:222:in `context' rack (2.0.0.rc1) lib/rack/session/abstract/id.rb:216:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/cookies.rb:613:in `call' activerecord (5.0.0.rc1) lib/active_record/migration.rb:552:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/callbacks.rb:38:in `block in call' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:97:in `__run_callbacks__' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:750:in `_run_call_callbacks' activesupport (5.0.0.rc1) lib/active_support/callbacks.rb:90:in `run_callbacks' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/callbacks.rb:36:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/executor.rb:12:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/remote_ip.rb:79:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/debug_exceptions.rb:49:in `call' web-console (3.1.1) lib/web_console/middleware.rb:131:in `call_app' web-console (3.1.1) lib/web_console/middleware.rb:28:in `block in call' web-console (3.1.1) lib/web_console/middleware.rb:18:in `catch' web-console (3.1.1) lib/web_console/middleware.rb:18:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/show_exceptions.rb:31:in `call' railties (5.0.0.rc1) lib/rails/rack/logger.rb:36:in `call_app' railties (5.0.0.rc1) lib/rails/rack/logger.rb:24:in `block in call' activesupport (5.0.0.rc1) lib/active_support/tagged_logging.rb:70:in `block in tagged' activesupport (5.0.0.rc1) lib/active_support/tagged_logging.rb:26:in `tagged' activesupport (5.0.0.rc1) lib/active_support/tagged_logging.rb:70:in `tagged' railties (5.0.0.rc1) lib/rails/rack/logger.rb:24:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/request_id.rb:24:in `call' rack (2.0.0.rc1) lib/rack/method_override.rb:22:in `call' rack (2.0.0.rc1) lib/rack/runtime.rb:22:in `call' activesupport (5.0.0.rc1) lib/active_support/cache/strategy/local_cache_middleware.rb:28:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/executor.rb:12:in `call' actionpack (5.0.0.rc1) lib/action_dispatch/middleware/static.rb:136:in `call' rack (2.0.0.rc1) lib/rack/sendfile.rb:111:in `call' rack-cors (0.4.0) lib/rack/cors.rb:80:in `call' railties (5.0.0.rc1) lib/rails/engine.rb:522:in `call' puma (3.4.0) lib/puma/configuration.rb:224:in `call' puma (3.4.0) lib/puma/server.rb:569:in `handle_request' puma (3.4.0) lib/puma/server.rb:406:in `process_client' puma (3.4.0) lib/puma/server.rb:271:in `block in run' puma (3.4.0) lib/puma/thread_pool.rb:114:in `block in spawn_thread'
I'm using resque-web 0.0.8 with Rails 5.0.0.rc1. Everything seems to work ok except the failures page which results in this error: