2017-07-24 16:20:53 -04:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
require "abstract_unit"
|
|
|
|
require "action_controller/metal/strong_parameters"
|
2012-07-12 01:50:42 -04:00
|
|
|
|
2016-03-13 03:36:08 -04:00
|
|
|
class NestedParametersPermitTest < ActiveSupport::TestCase
|
2013-01-20 11:59:53 -05:00
|
|
|
def assert_filtered_out(params, key)
|
2018-05-12 22:26:10 -04:00
|
|
|
assert_not params.has_key?(key), "key #{key.inspect} has not been filtered out"
|
2013-01-20 11:59:53 -05:00
|
|
|
end
|
|
|
|
|
2012-07-12 01:50:42 -04:00
|
|
|
test "permitted nested parameters" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2012-07-12 01:50:42 -04:00
|
|
|
title: "Romeo and Juliet",
|
|
|
|
authors: [{
|
|
|
|
name: "William Shakespeare",
|
|
|
|
born: "1564-04-26"
|
|
|
|
}, {
|
|
|
|
name: "Christopher Marlowe"
|
2013-01-20 11:59:53 -05:00
|
|
|
}, {
|
2013-01-22 07:40:33 -05:00
|
|
|
name: %w(malicious injected names)
|
2012-07-12 01:50:42 -04:00
|
|
|
}],
|
|
|
|
details: {
|
|
|
|
pages: 200,
|
|
|
|
genre: "Tragedy"
|
2012-10-11 22:50:20 -04:00
|
|
|
},
|
|
|
|
id: {
|
2016-08-06 12:54:50 -04:00
|
|
|
isbn: "x"
|
2012-07-12 01:50:42 -04:00
|
|
|
}
|
|
|
|
},
|
2016-08-06 13:44:11 -04:00
|
|
|
magazine: "Mjallo!")
|
2012-07-12 01:50:42 -04:00
|
|
|
|
2012-10-11 22:50:20 -04:00
|
|
|
permitted = params.permit book: [ :title, { authors: [ :name ] }, { details: :pages }, :id ]
|
2012-07-12 01:50:42 -04:00
|
|
|
|
2018-01-25 18:14:09 -05:00
|
|
|
assert_predicate permitted, :permitted?
|
2012-07-12 01:50:42 -04:00
|
|
|
assert_equal "Romeo and Juliet", permitted[:book][:title]
|
|
|
|
assert_equal "William Shakespeare", permitted[:book][:authors][0][:name]
|
|
|
|
assert_equal "Christopher Marlowe", permitted[:book][:authors][1][:name]
|
|
|
|
assert_equal 200, permitted[:book][:details][:pages]
|
2013-01-20 11:59:53 -05:00
|
|
|
|
|
|
|
assert_filtered_out permitted, :magazine
|
|
|
|
assert_filtered_out permitted[:book], :id
|
|
|
|
assert_filtered_out permitted[:book][:details], :genre
|
|
|
|
assert_filtered_out permitted[:book][:authors][0], :born
|
|
|
|
assert_filtered_out permitted[:book][:authors][2], :name
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
|
2012-11-30 11:24:16 -05:00
|
|
|
test "permitted nested parameters with a string or a symbol as a key" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2016-08-06 12:54:50 -04:00
|
|
|
"authors" => [
|
|
|
|
{ name: "William Shakespeare", born: "1564-04-26" },
|
|
|
|
{ name: "Christopher Marlowe" }
|
2012-11-30 11:24:16 -05:00
|
|
|
]
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2012-11-30 11:24:16 -05:00
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
permitted = params.permit book: [ { "authors" => [ :name ] } ]
|
2012-11-30 11:24:16 -05:00
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
assert_equal "William Shakespeare", permitted[:book]["authors"][0][:name]
|
|
|
|
assert_equal "William Shakespeare", permitted[:book][:authors][0][:name]
|
|
|
|
assert_equal "Christopher Marlowe", permitted[:book]["authors"][1][:name]
|
|
|
|
assert_equal "Christopher Marlowe", permitted[:book][:authors][1][:name]
|
2012-11-30 11:24:16 -05:00
|
|
|
|
|
|
|
permitted = params.permit book: [ { authors: [ :name ] } ]
|
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
assert_equal "William Shakespeare", permitted[:book]["authors"][0][:name]
|
|
|
|
assert_equal "William Shakespeare", permitted[:book][:authors][0][:name]
|
|
|
|
assert_equal "Christopher Marlowe", permitted[:book]["authors"][1][:name]
|
|
|
|
assert_equal "Christopher Marlowe", permitted[:book][:authors][1][:name]
|
2012-11-30 11:24:16 -05:00
|
|
|
end
|
|
|
|
|
2012-07-12 01:50:42 -04:00
|
|
|
test "nested arrays with strings" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2013-01-22 07:40:33 -05:00
|
|
|
genres: ["Tragedy"]
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2012-07-12 01:50:42 -04:00
|
|
|
|
2016-08-16 03:30:11 -04:00
|
|
|
permitted = params.permit book: { genres: [] }
|
2012-07-12 01:50:42 -04:00
|
|
|
assert_equal ["Tragedy"], permitted[:book][:genres]
|
|
|
|
end
|
|
|
|
|
|
|
|
test "permit may specify symbols or strings" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2013-01-22 07:40:33 -05:00
|
|
|
title: "Romeo and Juliet",
|
|
|
|
author: "William Shakespeare"
|
2012-07-12 01:50:42 -04:00
|
|
|
},
|
2016-08-06 13:44:11 -04:00
|
|
|
magazine: "Shakespeare Today")
|
2012-07-12 01:50:42 -04:00
|
|
|
|
2016-08-16 03:30:11 -04:00
|
|
|
permitted = params.permit({ book: ["title", :author] }, "magazine")
|
2012-07-12 01:50:42 -04:00
|
|
|
assert_equal "Romeo and Juliet", permitted[:book][:title]
|
|
|
|
assert_equal "William Shakespeare", permitted[:book][:author]
|
|
|
|
assert_equal "Shakespeare Today", permitted[:magazine]
|
|
|
|
end
|
|
|
|
|
|
|
|
test "nested array with strings that should be hashes" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2012-07-12 01:50:42 -04:00
|
|
|
genres: ["Tragedy"]
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2012-07-12 01:50:42 -04:00
|
|
|
|
|
|
|
permitted = params.permit book: { genres: :type }
|
|
|
|
assert_empty permitted[:book][:genres]
|
|
|
|
end
|
|
|
|
|
|
|
|
test "nested array with strings that should be hashes and additional values" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2012-07-12 01:50:42 -04:00
|
|
|
title: "Romeo and Juliet",
|
|
|
|
genres: ["Tragedy"]
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2012-07-12 01:50:42 -04:00
|
|
|
|
|
|
|
permitted = params.permit book: [ :title, { genres: :type } ]
|
|
|
|
assert_equal "Romeo and Juliet", permitted[:book][:title]
|
|
|
|
assert_empty permitted[:book][:genres]
|
|
|
|
end
|
|
|
|
|
|
|
|
test "nested string that should be a hash" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2012-07-12 01:50:42 -04:00
|
|
|
genre: "Tragedy"
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2012-07-12 01:50:42 -04:00
|
|
|
|
|
|
|
permitted = params.permit book: { genre: :type }
|
|
|
|
assert_nil permitted[:book][:genre]
|
|
|
|
end
|
2012-09-01 03:30:07 -04:00
|
|
|
|
2017-08-01 14:02:41 -04:00
|
|
|
test "nested params with numeric keys" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2013-01-22 07:40:33 -05:00
|
|
|
authors_attributes: {
|
2016-08-06 13:35:13 -04:00
|
|
|
'0': { name: "William Shakespeare", age_of_death: "52" },
|
|
|
|
'1': { name: "Unattributed Assistant" },
|
|
|
|
'2': { name: %w(injected names) }
|
2012-09-01 03:30:07 -04:00
|
|
|
}
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2013-01-22 07:40:33 -05:00
|
|
|
permitted = params.permit book: { authors_attributes: [ :name ] }
|
2012-09-01 03:30:07 -04:00
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
assert_not_nil permitted[:book][:authors_attributes]["0"]
|
|
|
|
assert_not_nil permitted[:book][:authors_attributes]["1"]
|
|
|
|
assert_empty permitted[:book][:authors_attributes]["2"]
|
|
|
|
assert_equal "William Shakespeare", permitted[:book][:authors_attributes]["0"][:name]
|
|
|
|
assert_equal "Unattributed Assistant", permitted[:book][:authors_attributes]["1"][:name]
|
2013-01-20 11:59:53 -05:00
|
|
|
|
2017-01-16 08:08:48 -05:00
|
|
|
assert_equal(
|
2017-01-17 22:10:14 -05:00
|
|
|
{ "book" => { "authors_attributes" => { "0" => { "name" => "William Shakespeare" }, "1" => { "name" => "Unattributed Assistant" }, "2" => {} } } },
|
2017-01-16 08:08:48 -05:00
|
|
|
permitted.to_h
|
|
|
|
)
|
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
assert_filtered_out permitted[:book][:authors_attributes]["0"], :age_of_death
|
2013-01-20 11:59:53 -05:00
|
|
|
end
|
|
|
|
|
2017-08-01 14:02:41 -04:00
|
|
|
test "nested params with non_numeric keys" do
|
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
|
|
|
authors_attributes: {
|
|
|
|
'0': { name: "William Shakespeare", age_of_death: "52" },
|
|
|
|
'1': { name: "Unattributed Assistant" },
|
|
|
|
'2': "Not a hash",
|
|
|
|
'new_record': { name: "Some name" }
|
|
|
|
}
|
|
|
|
})
|
|
|
|
permitted = params.permit book: { authors_attributes: [ :name ] }
|
|
|
|
|
|
|
|
assert_not_nil permitted[:book][:authors_attributes]["0"]
|
|
|
|
assert_not_nil permitted[:book][:authors_attributes]["1"]
|
|
|
|
|
|
|
|
assert_nil permitted[:book][:authors_attributes]["2"]
|
|
|
|
assert_nil permitted[:book][:authors_attributes]["new_record"]
|
|
|
|
assert_equal "William Shakespeare", permitted[:book][:authors_attributes]["0"][:name]
|
|
|
|
assert_equal "Unattributed Assistant", permitted[:book][:authors_attributes]["1"][:name]
|
|
|
|
|
|
|
|
assert_equal(
|
|
|
|
{ "book" => { "authors_attributes" => { "0" => { "name" => "William Shakespeare" }, "1" => { "name" => "Unattributed Assistant" } } } },
|
|
|
|
permitted.to_h
|
|
|
|
)
|
|
|
|
end
|
|
|
|
|
|
|
|
test "nested params with negative numeric keys" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
2013-01-22 07:40:33 -05:00
|
|
|
authors_attributes: {
|
2016-08-06 13:35:13 -04:00
|
|
|
'-1': { name: "William Shakespeare", age_of_death: "52" },
|
|
|
|
'-2': { name: "Unattributed Assistant" }
|
2013-01-20 11:59:53 -05:00
|
|
|
}
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2013-01-22 07:40:33 -05:00
|
|
|
permitted = params.permit book: { authors_attributes: [:name] }
|
2013-01-20 11:59:53 -05:00
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
assert_not_nil permitted[:book][:authors_attributes]["-1"]
|
|
|
|
assert_not_nil permitted[:book][:authors_attributes]["-2"]
|
|
|
|
assert_equal "William Shakespeare", permitted[:book][:authors_attributes]["-1"][:name]
|
|
|
|
assert_equal "Unattributed Assistant", permitted[:book][:authors_attributes]["-2"][:name]
|
2013-01-20 11:59:53 -05:00
|
|
|
|
2016-08-06 12:54:50 -04:00
|
|
|
assert_filtered_out permitted[:book][:authors_attributes]["-1"], :age_of_death
|
2012-09-01 03:30:07 -04:00
|
|
|
end
|
2013-09-22 10:57:21 -04:00
|
|
|
|
Allow permitting numeric params
When specifying numeric parameters, strong params lets you permit them all using the same permitted params for each.
For example params like,
```ruby
book: {
authors_attributes: {
'0': { name: "William Shakespeare", age_of_death: "52" },
'1': { name: "Unattributed Assistant" },
'2': "Not a hash",
'new_record': { name: "Some name" }
}
}
```
can be permitted with,
```
permit book: { authors_attributes: [ :name ] }
```
This returns the name keys for each of the numeric keyed params that have a name field,
```ruby
{ "book" => { "authors_attributes" => { "0" => { "name" => "William Shakespeare" }, "1" => { "name" => "Unattributed Assistant" } } } }
```
This is exactly what you want most of the time. Rarely you might need
to specify different keys for particular numeric attributes. This
allows another strong params syntax for those cases where you can
specify the keys allowed for each individual numerically keys attributes
hash.
After this change using the same params above, you can permit the name and age for only the `0` key and only the name for the `1` key,
```ruby
permit book: { authors_attributes: { '1': [ :name ], '0': [ :name, :age_of_death ] } }
```
This returns exactly the parameters that you specify,
```ruby
{ "book" => { "authors_attributes" => { "0" => { "name" => "William Shakespeare", "age_of_death" => "52" }, "1" => { "name" => "Unattributed Assistant" } } } }
```
Sidenote: this allows `permit` to do the equivalent to
```ruby
params.require(:book).permit(authors_attributes: { '1': [:name]})
```
without raising when `book: ... ` is not present.
The simpler syntax should be preferred, but in cases where you need more control, this is a nice option to have.
2021-06-15 17:08:16 -04:00
|
|
|
test "nested params with numeric keys addressing individual numeric keys" do
|
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
|
|
|
authors_attributes: {
|
|
|
|
'0': { name: "William Shakespeare", age_of_death: "52" },
|
|
|
|
'1': { name: "Unattributed Assistant" },
|
|
|
|
'2': { name: %w(injected names) }
|
|
|
|
}
|
|
|
|
})
|
|
|
|
permitted = params.permit book: { authors_attributes: { '1': [ :name ], '0': [ :name, :age_of_death ] } }
|
|
|
|
|
|
|
|
assert_equal(
|
|
|
|
{ "book" => { "authors_attributes" => { "0" => { "name" => "William Shakespeare", "age_of_death" => "52" }, "1" => { "name" => "Unattributed Assistant" } } } },
|
|
|
|
permitted.to_h
|
|
|
|
)
|
|
|
|
end
|
|
|
|
|
|
|
|
test "nested params with numeric keys addressing individual numeric keys using require first" do
|
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
|
|
|
authors_attributes: {
|
|
|
|
'0': { name: "William Shakespeare", age_of_death: "52" },
|
|
|
|
'1': { name: "Unattributed Assistant" },
|
|
|
|
'2': { name: %w(injected names) }
|
|
|
|
}
|
|
|
|
})
|
|
|
|
|
|
|
|
permitted = params.require(:book).permit(authors_attributes: { '1': [:name] })
|
|
|
|
|
|
|
|
assert_equal(
|
|
|
|
{ "authors_attributes" => { "1" => { "name" => "Unattributed Assistant" } } },
|
|
|
|
permitted.to_h
|
|
|
|
)
|
|
|
|
end
|
|
|
|
|
|
|
|
test "nested params with numeric keys addressing individual numeric keys to arrays" do
|
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
|
|
|
authors_attributes: {
|
|
|
|
'0': ["draft 1", "draft 2", "draft 3"],
|
|
|
|
'1': ["final draft"],
|
|
|
|
'2': { name: %w(injected names) }
|
|
|
|
}
|
|
|
|
})
|
|
|
|
permitted = params.permit book: { authors_attributes: { '2': [ :name ], '0': [] } }
|
|
|
|
|
|
|
|
assert_equal(
|
|
|
|
{ "book" => { "authors_attributes" => { "2" => {}, "0" => ["draft 1", "draft 2", "draft 3"] } } },
|
|
|
|
permitted.to_h
|
|
|
|
)
|
|
|
|
end
|
|
|
|
|
|
|
|
test "nested params with numeric keys addressing individual numeric keys to more nested params" do
|
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
book: {
|
|
|
|
authors_attributes: {
|
|
|
|
'0': ["draft 1", "draft 2", "draft 3"],
|
|
|
|
'1': ["final draft"],
|
|
|
|
'2': { name: { "projects" => [ "hamlet", "Othello" ] } }
|
|
|
|
}
|
|
|
|
})
|
|
|
|
permitted = params.permit book: { authors_attributes: { '2': { name: { projects: [] } }, '0': [] } }
|
|
|
|
|
|
|
|
assert_equal(
|
|
|
|
{ "book" => { "authors_attributes" => { "2" => { "name" => { "projects" => ["hamlet", "Othello"] } }, "0" => ["draft 1", "draft 2", "draft 3"] } } },
|
|
|
|
permitted.to_h
|
|
|
|
)
|
|
|
|
end
|
|
|
|
|
2013-09-22 10:57:21 -04:00
|
|
|
test "nested number as key" do
|
2016-08-09 17:36:39 -04:00
|
|
|
params = ActionController::Parameters.new(
|
|
|
|
product: {
|
2013-09-22 10:57:21 -04:00
|
|
|
properties: {
|
2016-08-06 12:54:50 -04:00
|
|
|
"0" => "prop0",
|
|
|
|
"1" => "prop1"
|
2013-09-22 10:57:21 -04:00
|
|
|
}
|
2016-08-06 13:44:11 -04:00
|
|
|
})
|
2016-08-06 13:35:13 -04:00
|
|
|
params = params.require(:product).permit(properties: ["0"])
|
2013-09-22 10:57:21 -04:00
|
|
|
assert_not_nil params[:properties]["0"]
|
|
|
|
assert_nil params[:properties]["1"]
|
|
|
|
assert_equal "prop0", params[:properties]["0"]
|
|
|
|
end
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|