Hacker News new | past | comments | ask | show | jobs | submit login

Actually, I do use update_attributes for public-facing interfaces. But only with attr_accessible. (I never use attr_protected, since blacklists are a disaster waiting to happen.)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: