2012-07-12 01:50:42 -04:00
|
|
|
require 'active_support/core_ext/hash/indifferent_access'
|
2012-12-13 12:48:55 -05:00
|
|
|
require 'active_support/core_ext/array/wrap'
|
2014-10-28 19:17:33 -04:00
|
|
|
require 'active_support/core_ext/string/filters'
|
2014-06-27 02:01:30 -04:00
|
|
|
require 'active_support/deprecation'
|
2012-07-12 01:50:42 -04:00
|
|
|
require 'active_support/rescuable'
|
2013-01-23 17:14:47 -05:00
|
|
|
require 'action_dispatch/http/upload'
|
2013-03-22 10:16:02 -04:00
|
|
|
require 'stringio'
|
2013-12-21 08:22:08 -05:00
|
|
|
require 'set'
|
2012-07-12 01:50:42 -04:00
|
|
|
|
|
|
|
module ActionController
|
2012-09-18 23:29:25 -04:00
|
|
|
# Raised when a required parameter is missing.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(a: {})
|
|
|
|
# params.fetch(:b)
|
2012-09-27 15:27:02 -04:00
|
|
|
# # => ActionController::ParameterMissing: param not found: b
|
2013-11-02 15:30:03 -04:00
|
|
|
# params.require(:a)
|
|
|
|
# # => ActionController::ParameterMissing: param not found: a
|
2012-09-10 02:48:31 -04:00
|
|
|
class ParameterMissing < KeyError
|
2012-09-18 23:29:25 -04:00
|
|
|
attr_reader :param # :nodoc:
|
2012-07-12 01:50:42 -04:00
|
|
|
|
2012-09-18 23:29:25 -04:00
|
|
|
def initialize(param) # :nodoc:
|
2012-07-12 01:50:42 -04:00
|
|
|
@param = param
|
2013-11-02 15:39:40 -04:00
|
|
|
super("param is missing or the value is empty: #{param}")
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2013-01-19 09:20:13 -05:00
|
|
|
# Raised when a supplied parameter is not expected.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(a: "123", b: "456")
|
|
|
|
# params.permit(:c)
|
2013-01-19 12:32:27 -05:00
|
|
|
# # => ActionController::UnpermittedParameters: found unexpected keys: a, b
|
|
|
|
class UnpermittedParameters < IndexError
|
|
|
|
attr_reader :params # :nodoc:
|
2013-01-19 09:20:13 -05:00
|
|
|
|
2013-01-19 12:32:27 -05:00
|
|
|
def initialize(params) # :nodoc:
|
2013-01-19 09:20:13 -05:00
|
|
|
@params = params
|
2014-02-24 04:25:38 -05:00
|
|
|
super("found unpermitted parameter#{'s' if params.size > 1 }: #{params.join(", ")}")
|
2013-01-19 09:20:13 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-10-18 13:44:28 -04:00
|
|
|
# == Action Controller \Parameters
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
|
|
|
# Allows to choose which attributes should be whitelisted for mass updating
|
2014-06-27 02:01:30 -04:00
|
|
|
# and thus prevent accidentally exposing that which shouldn't be exposed.
|
2012-09-19 21:53:34 -04:00
|
|
|
# Provides two methods for this purpose: #require and #permit. The former is
|
|
|
|
# used to mark parameters as required. The latter is used to set the parameter
|
2012-10-18 13:44:28 -04:00
|
|
|
# as permitted and limit which attributes should be allowed for mass updating.
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new({
|
|
|
|
# person: {
|
|
|
|
# name: 'Francesco',
|
|
|
|
# age: 22,
|
|
|
|
# role: 'admin'
|
|
|
|
# }
|
|
|
|
# })
|
|
|
|
#
|
|
|
|
# permitted = params.require(:person).permit(:name, :age)
|
|
|
|
# permitted # => {"name"=>"Francesco", "age"=>22}
|
|
|
|
# permitted.class # => ActionController::Parameters
|
|
|
|
# permitted.permitted? # => true
|
|
|
|
#
|
2013-01-02 16:16:24 -05:00
|
|
|
# Person.first.update!(permitted)
|
2012-09-19 22:13:43 -04:00
|
|
|
# # => #<Person id: 1, name: "Francesco", age: 22, role: "user">
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
2013-01-19 12:32:27 -05:00
|
|
|
# It provides two options that controls the top-level behavior of new instances:
|
|
|
|
#
|
|
|
|
# * +permit_all_parameters+ - If it's +true+, all the parameters will be
|
|
|
|
# permitted by default. The default is +false+.
|
|
|
|
# * +action_on_unpermitted_parameters+ - Allow to control the behavior when parameters
|
|
|
|
# that are not explicitly permitted are found. The values can be <tt>:log</tt> to
|
|
|
|
# write a message on the logger or <tt>:raise</tt> to raise
|
|
|
|
# ActionController::UnpermittedParameters exception. The default value is <tt>:log</tt>
|
|
|
|
# in test and development environments, +false+ otherwise.
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
2013-03-23 14:38:11 -04:00
|
|
|
# Examples:
|
|
|
|
#
|
2012-09-19 21:53:34 -04:00
|
|
|
# params = ActionController::Parameters.new
|
2012-09-19 23:33:50 -04:00
|
|
|
# params.permitted? # => false
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
|
|
|
# ActionController::Parameters.permit_all_parameters = true
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new
|
|
|
|
# params.permitted? # => true
|
|
|
|
#
|
2013-01-19 12:32:27 -05:00
|
|
|
# params = ActionController::Parameters.new(a: "123", b: "456")
|
|
|
|
# params.permit(:c)
|
|
|
|
# # => {}
|
|
|
|
#
|
|
|
|
# ActionController::Parameters.action_on_unpermitted_parameters = :raise
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(a: "123", b: "456")
|
|
|
|
# params.permit(:c)
|
|
|
|
# # => ActionController::UnpermittedParameters: found unpermitted keys: a, b
|
|
|
|
#
|
2014-12-19 04:14:26 -05:00
|
|
|
# Please note that these options *are not thread-safe*. In a multi-threaded
|
|
|
|
# environment they should only be set once at boot-time and never mutated at
|
|
|
|
# runtime.
|
|
|
|
#
|
|
|
|
# <tt>ActionController::Parameters</tt> inherits from
|
2012-09-19 21:53:34 -04:00
|
|
|
# <tt>ActiveSupport::HashWithIndifferentAccess</tt>, this means
|
|
|
|
# that you can fetch values using either <tt>:key</tt> or <tt>"key"</tt>.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(key: 'value')
|
|
|
|
# params[:key] # => "value"
|
|
|
|
# params["key"] # => "value"
|
2012-07-12 01:50:42 -04:00
|
|
|
class Parameters < ActiveSupport::HashWithIndifferentAccess
|
2014-12-19 04:14:26 -05:00
|
|
|
cattr_accessor :permit_all_parameters, instance_accessor: false
|
2013-01-19 12:32:27 -05:00
|
|
|
cattr_accessor :action_on_unpermitted_parameters, instance_accessor: false
|
|
|
|
|
2014-06-27 02:01:30 -04:00
|
|
|
# By default, never raise an UnpermittedParameters exception if these
|
|
|
|
# params are present. The default includes both 'controller' and 'action'
|
|
|
|
# because they are added by Rails and should be of no concern. One way
|
|
|
|
# to change these is to specify `always_permitted_parameters` in your
|
2014-06-27 16:08:40 -04:00
|
|
|
# config. For instance:
|
|
|
|
#
|
|
|
|
# config.always_permitted_parameters = %w( controller action format )
|
2014-06-27 02:01:30 -04:00
|
|
|
cattr_accessor :always_permitted_parameters
|
|
|
|
self.always_permitted_parameters = %w( controller action )
|
|
|
|
|
|
|
|
def self.const_missing(const_name)
|
|
|
|
super unless const_name == :NEVER_UNPERMITTED_PARAMS
|
2014-10-28 19:17:33 -04:00
|
|
|
ActiveSupport::Deprecation.warn(<<-MSG.squish)
|
|
|
|
`ActionController::Parameters::NEVER_UNPERMITTED_PARAMS` has been deprecated.
|
|
|
|
Use `ActionController::Parameters.always_permitted_parameters` instead.
|
|
|
|
MSG
|
|
|
|
|
|
|
|
always_permitted_parameters
|
2014-06-27 02:01:30 -04:00
|
|
|
end
|
2013-01-08 09:52:00 -05:00
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Returns a new instance of <tt>ActionController::Parameters</tt>.
|
|
|
|
# Also, sets the +permitted+ attribute to the default value of
|
|
|
|
# <tt>ActionController::Parameters.permit_all_parameters</tt>.
|
|
|
|
#
|
2012-11-27 08:11:30 -05:00
|
|
|
# class Person < ActiveRecord::Base
|
2012-09-19 21:53:34 -04:00
|
|
|
# end
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(name: 'Francesco')
|
|
|
|
# params.permitted? # => false
|
2012-10-18 13:44:28 -04:00
|
|
|
# Person.new(params) # => ActiveModel::ForbiddenAttributesError
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
|
|
|
# ActionController::Parameters.permit_all_parameters = true
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(name: 'Francesco')
|
2012-10-18 13:44:28 -04:00
|
|
|
# params.permitted? # => true
|
2012-09-19 21:53:34 -04:00
|
|
|
# Person.new(params) # => #<Person id: nil, name: "Francesco">
|
2012-07-12 01:50:42 -04:00
|
|
|
def initialize(attributes = nil)
|
|
|
|
super(attributes)
|
2012-08-30 17:36:59 -04:00
|
|
|
@permitted = self.class.permit_all_parameters
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
|
2014-07-25 12:00:14 -04:00
|
|
|
# Returns a safe +Hash+ representation of this parameter with all
|
|
|
|
# unpermitted keys removed.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new({
|
|
|
|
# name: 'Senjougahara Hitagi',
|
|
|
|
# oddity: 'Heavy stone crab'
|
|
|
|
# })
|
|
|
|
# params.to_h # => {}
|
|
|
|
#
|
|
|
|
# safe_params = params.permit(:name)
|
|
|
|
# safe_params.to_h # => {"name"=>"Senjougahara Hitagi"}
|
|
|
|
def to_h
|
|
|
|
if permitted?
|
2014-08-18 23:42:42 -04:00
|
|
|
to_hash
|
2014-07-25 12:00:14 -04:00
|
|
|
else
|
|
|
|
slice(*self.class.always_permitted_parameters).permit!.to_h
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2014-12-12 06:48:42 -05:00
|
|
|
# Returns an unsafe, unfiltered +Hash+ representation of this parameter.
|
|
|
|
def to_unsafe_h
|
|
|
|
to_hash
|
|
|
|
end
|
|
|
|
alias_method :to_unsafe_hash, :to_unsafe_h
|
|
|
|
|
2014-08-18 20:39:00 -04:00
|
|
|
# Convert all hashes in values into parameters, then yield each pair like
|
|
|
|
# the same way as <tt>Hash#each_pair</tt>
|
|
|
|
def each_pair(&block)
|
|
|
|
super do |key, value|
|
|
|
|
convert_hashes_to_parameters(key, value)
|
|
|
|
end
|
|
|
|
|
|
|
|
super
|
|
|
|
end
|
|
|
|
|
|
|
|
alias_method :each, :each_pair
|
|
|
|
|
2013-12-21 08:22:08 -05:00
|
|
|
# Attribute that keeps track of converted arrays, if any, to avoid double
|
|
|
|
# looping in the common use case permit + mass-assignment. Defined in a
|
|
|
|
# method to instantiate it only if needed.
|
2014-06-07 07:30:03 -04:00
|
|
|
#
|
|
|
|
# Testing membership still loops, but it's going to be faster than our own
|
|
|
|
# loop that converts values. Also, we are not going to build a new array
|
|
|
|
# object per fetch.
|
2013-12-21 08:22:08 -05:00
|
|
|
def converted_arrays
|
2014-06-07 07:04:40 -04:00
|
|
|
@converted_arrays ||= Set.new
|
2013-12-21 08:22:08 -05:00
|
|
|
end
|
|
|
|
|
2012-09-19 22:13:43 -04:00
|
|
|
# Returns +true+ if the parameter is permitted, +false+ otherwise.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new
|
|
|
|
# params.permitted? # => false
|
|
|
|
# params.permit!
|
|
|
|
# params.permitted? # => true
|
|
|
|
def permitted?
|
|
|
|
@permitted
|
|
|
|
end
|
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Sets the +permitted+ attribute to +true+. This can be used to pass
|
|
|
|
# mass assignment. Returns +self+.
|
|
|
|
#
|
|
|
|
# class Person < ActiveRecord::Base
|
|
|
|
# end
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(name: 'Francesco')
|
2012-10-18 02:38:36 -04:00
|
|
|
# params.permitted? # => false
|
2012-09-19 21:53:34 -04:00
|
|
|
# Person.new(params) # => ActiveModel::ForbiddenAttributesError
|
|
|
|
# params.permit!
|
|
|
|
# params.permitted? # => true
|
|
|
|
# Person.new(params) # => #<Person id: nil, name: "Francesco">
|
2012-07-12 01:50:42 -04:00
|
|
|
def permit!
|
2012-10-04 14:51:08 -04:00
|
|
|
each_pair do |key, value|
|
2014-06-05 15:17:11 -04:00
|
|
|
Array.wrap(value).each do |v|
|
|
|
|
v.permit! if v.respond_to? :permit!
|
2013-12-23 16:55:03 -05:00
|
|
|
end
|
2012-10-04 14:51:08 -04:00
|
|
|
end
|
|
|
|
|
2012-07-12 01:50:42 -04:00
|
|
|
@permitted = true
|
|
|
|
self
|
|
|
|
end
|
|
|
|
|
2013-11-02 15:30:03 -04:00
|
|
|
# Ensures that a parameter is present. If it's present, returns
|
|
|
|
# the parameter at the given +key+, otherwise raises an
|
|
|
|
# <tt>ActionController::ParameterMissing</tt> error.
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
2012-10-18 02:38:36 -04:00
|
|
|
# ActionController::Parameters.new(person: { name: 'Francesco' }).require(:person)
|
2012-11-30 11:24:16 -05:00
|
|
|
# # => {"name"=>"Francesco"}
|
2012-09-19 21:53:34 -04:00
|
|
|
#
|
2013-11-02 15:30:03 -04:00
|
|
|
# ActionController::Parameters.new(person: nil).require(:person)
|
|
|
|
# # => ActionController::ParameterMissing: param not found: person
|
2013-03-11 09:00:19 -04:00
|
|
|
#
|
2013-11-02 15:30:03 -04:00
|
|
|
# ActionController::Parameters.new(person: {}).require(:person)
|
2012-09-27 15:27:02 -04:00
|
|
|
# # => ActionController::ParameterMissing: param not found: person
|
2012-07-12 01:50:42 -04:00
|
|
|
def require(key)
|
2014-06-13 16:23:45 -04:00
|
|
|
value = self[key]
|
|
|
|
if value.present? || value == false
|
|
|
|
value
|
|
|
|
else
|
|
|
|
raise ParameterMissing.new(key)
|
|
|
|
end
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Alias of #require.
|
2012-07-12 01:50:42 -04:00
|
|
|
alias :required :require
|
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Returns a new <tt>ActionController::Parameters</tt> instance that
|
2012-10-18 13:44:28 -04:00
|
|
|
# includes only the given +filters+ and sets the +permitted+ attribute
|
|
|
|
# for the object to +true+. This is useful for limiting which attributes
|
2012-09-19 21:53:34 -04:00
|
|
|
# should be allowed for mass updating.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(user: { name: 'Francesco', age: 22, role: 'admin' })
|
|
|
|
# permitted = params.require(:user).permit(:name, :age)
|
2012-10-18 02:38:36 -04:00
|
|
|
# permitted.permitted? # => true
|
2012-09-19 21:53:34 -04:00
|
|
|
# permitted.has_key?(:name) # => true
|
|
|
|
# permitted.has_key?(:age) # => true
|
|
|
|
# permitted.has_key?(:role) # => false
|
|
|
|
#
|
2013-01-20 11:59:53 -05:00
|
|
|
# Only permitted scalars pass the filter. For example, given
|
|
|
|
#
|
|
|
|
# params.permit(:name)
|
|
|
|
#
|
|
|
|
# +:name+ passes it is a key of +params+ whose associated value is of type
|
|
|
|
# +String+, +Symbol+, +NilClass+, +Numeric+, +TrueClass+, +FalseClass+,
|
2013-02-21 09:00:26 -05:00
|
|
|
# +Date+, +Time+, +DateTime+, +StringIO+, +IO+,
|
|
|
|
# +ActionDispatch::Http::UploadedFile+ or +Rack::Test::UploadedFile+.
|
|
|
|
# Otherwise, the key +:name+ is filtered out.
|
2013-01-20 11:59:53 -05:00
|
|
|
#
|
|
|
|
# You may declare that the parameter should be an array of permitted scalars
|
|
|
|
# by mapping it to an empty array:
|
|
|
|
#
|
2013-08-05 09:40:54 -04:00
|
|
|
# params = ActionController::Parameters.new(tags: ['rails', 'parameters'])
|
2013-01-20 18:58:24 -05:00
|
|
|
# params.permit(tags: [])
|
2013-01-20 11:59:53 -05:00
|
|
|
#
|
2012-09-19 21:53:34 -04:00
|
|
|
# You can also use +permit+ on nested parameters, like:
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new({
|
2012-10-18 02:38:36 -04:00
|
|
|
# person: {
|
2012-09-19 21:53:34 -04:00
|
|
|
# name: 'Francesco',
|
|
|
|
# age: 22,
|
|
|
|
# pets: [{
|
|
|
|
# name: 'Purplish',
|
|
|
|
# category: 'dogs'
|
|
|
|
# }]
|
|
|
|
# }
|
|
|
|
# })
|
|
|
|
#
|
2012-12-05 01:11:54 -05:00
|
|
|
# permitted = params.permit(person: [ :name, { pets: :name } ])
|
2012-09-19 21:53:34 -04:00
|
|
|
# permitted.permitted? # => true
|
|
|
|
# permitted[:person][:name] # => "Francesco"
|
2012-10-18 02:38:36 -04:00
|
|
|
# permitted[:person][:age] # => nil
|
2012-09-19 21:53:34 -04:00
|
|
|
# permitted[:person][:pets][0][:name] # => "Purplish"
|
|
|
|
# permitted[:person][:pets][0][:category] # => nil
|
2012-10-11 23:41:01 -04:00
|
|
|
#
|
|
|
|
# Note that if you use +permit+ in a key that points to a hash,
|
|
|
|
# it won't allow all the hash. You also need to specify which
|
|
|
|
# attributes inside the hash should be whitelisted.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new({
|
|
|
|
# person: {
|
|
|
|
# contact: {
|
2013-04-24 08:21:24 -04:00
|
|
|
# email: 'none@test.com',
|
2012-10-11 23:41:01 -04:00
|
|
|
# phone: '555-1234'
|
|
|
|
# }
|
|
|
|
# }
|
|
|
|
# })
|
|
|
|
#
|
|
|
|
# params.require(:person).permit(:contact)
|
|
|
|
# # => {}
|
|
|
|
#
|
|
|
|
# params.require(:person).permit(contact: :phone)
|
2012-11-30 11:24:16 -05:00
|
|
|
# # => {"contact"=>{"phone"=>"555-1234"}}
|
2012-10-11 23:41:01 -04:00
|
|
|
#
|
|
|
|
# params.require(:person).permit(contact: [ :email, :phone ])
|
|
|
|
# # => {"contact"=>{"email"=>"none@test.com", "phone"=>"555-1234"}}
|
2012-07-12 01:50:42 -04:00
|
|
|
def permit(*filters)
|
|
|
|
params = self.class.new
|
|
|
|
|
2012-10-31 11:32:24 -04:00
|
|
|
filters.flatten.each do |filter|
|
2012-07-12 01:50:42 -04:00
|
|
|
case filter
|
2013-01-20 11:59:53 -05:00
|
|
|
when Symbol, String
|
|
|
|
permitted_scalar_filter(params, filter)
|
2012-07-12 01:50:42 -04:00
|
|
|
when Hash then
|
2013-01-20 11:59:53 -05:00
|
|
|
hash_filter(params, filter)
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2013-01-22 07:36:46 -05:00
|
|
|
unpermitted_parameters!(params) if self.class.action_on_unpermitted_parameters
|
2013-01-19 12:32:27 -05:00
|
|
|
|
2012-07-12 01:50:42 -04:00
|
|
|
params.permit!
|
|
|
|
end
|
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Returns a parameter for the given +key+. If not found,
|
|
|
|
# returns +nil+.
|
|
|
|
#
|
2012-12-05 01:11:54 -05:00
|
|
|
# params = ActionController::Parameters.new(person: { name: 'Francesco' })
|
2012-10-18 02:38:36 -04:00
|
|
|
# params[:person] # => {"name"=>"Francesco"}
|
2012-09-19 21:53:34 -04:00
|
|
|
# params[:none] # => nil
|
2012-07-12 01:50:42 -04:00
|
|
|
def [](key)
|
|
|
|
convert_hashes_to_parameters(key, super)
|
|
|
|
end
|
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Returns a parameter for the given +key+. If the +key+
|
|
|
|
# can't be found, there are several options: With no other arguments,
|
|
|
|
# it will raise an <tt>ActionController::ParameterMissing</tt> error;
|
|
|
|
# if more arguments are given, then that will be returned; if a block
|
|
|
|
# is given, then that will be run and its result returned.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(person: { name: 'Francesco' })
|
2012-10-18 02:38:36 -04:00
|
|
|
# params.fetch(:person) # => {"name"=>"Francesco"}
|
|
|
|
# params.fetch(:none) # => ActionController::ParameterMissing: param not found: none
|
2012-09-19 21:53:34 -04:00
|
|
|
# params.fetch(:none, 'Francesco') # => "Francesco"
|
2012-10-18 02:38:36 -04:00
|
|
|
# params.fetch(:none) { 'Francesco' } # => "Francesco"
|
2012-07-12 01:50:42 -04:00
|
|
|
def fetch(key, *args)
|
2013-12-21 07:41:46 -05:00
|
|
|
convert_hashes_to_parameters(key, super, false)
|
2012-07-12 01:50:42 -04:00
|
|
|
rescue KeyError
|
|
|
|
raise ActionController::ParameterMissing.new(key)
|
|
|
|
end
|
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Returns a new <tt>ActionController::Parameters</tt> instance that
|
|
|
|
# includes only the given +keys+. If the given +keys+
|
|
|
|
# don't exist, returns an empty hash.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(a: 1, b: 2, c: 3)
|
|
|
|
# params.slice(:a, :b) # => {"a"=>1, "b"=>2}
|
|
|
|
# params.slice(:d) # => {}
|
2012-07-12 01:50:42 -04:00
|
|
|
def slice(*keys)
|
2014-07-25 16:23:38 -04:00
|
|
|
new_instance_with_inherited_permitted_status(super)
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
|
2014-07-25 16:16:58 -04:00
|
|
|
# Removes and returns the key/value pairs matching the given keys.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(a: 1, b: 2, c: 3)
|
|
|
|
# params.extract!(:a, :b) # => {"a"=>1, "b"=>2}
|
|
|
|
# params # => {"c"=>3}
|
|
|
|
def extract!(*keys)
|
2014-07-25 16:23:38 -04:00
|
|
|
new_instance_with_inherited_permitted_status(super)
|
2014-07-25 16:16:58 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
# Returns a new <tt>ActionController::Parameters</tt> with the results of
|
|
|
|
# running +block+ once for every value. The keys are unchanged.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(a: 1, b: 2, c: 3)
|
|
|
|
# params.transform_values { |x| x * 2 }
|
|
|
|
# # => {"a"=>2, "b"=>4, "c"=>6}
|
|
|
|
def transform_values
|
|
|
|
if block_given?
|
2014-07-25 16:23:38 -04:00
|
|
|
new_instance_with_inherited_permitted_status(super)
|
2014-07-25 16:16:58 -04:00
|
|
|
else
|
|
|
|
super
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# This method is here only to make sure that the returned object has the
|
|
|
|
# correct +permitted+ status. It should not matter since the parent of
|
|
|
|
# this object is +HashWithIndifferentAccess+
|
|
|
|
def transform_keys # :nodoc:
|
|
|
|
if block_given?
|
2014-07-25 16:23:38 -04:00
|
|
|
new_instance_with_inherited_permitted_status(super)
|
2014-07-25 16:16:58 -04:00
|
|
|
else
|
|
|
|
super
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2014-08-18 20:39:00 -04:00
|
|
|
# Deletes and returns a key-value pair from +Parameters+ whose key is equal
|
|
|
|
# to key. If the key is not found, returns the default value. If the
|
|
|
|
# optional code block is given and the key is not found, pass in the key
|
|
|
|
# and return the result of block.
|
|
|
|
def delete(key, &block)
|
|
|
|
convert_hashes_to_parameters(key, super, false)
|
|
|
|
end
|
|
|
|
|
|
|
|
# Equivalent to Hash#keep_if, but returns nil if no changes were made.
|
|
|
|
def select!(&block)
|
|
|
|
convert_value_to_parameters(super)
|
|
|
|
end
|
|
|
|
|
2012-09-19 21:53:34 -04:00
|
|
|
# Returns an exact copy of the <tt>ActionController::Parameters</tt>
|
|
|
|
# instance. +permitted+ state is kept on the duped object.
|
|
|
|
#
|
|
|
|
# params = ActionController::Parameters.new(a: 1)
|
|
|
|
# params.permit!
|
|
|
|
# params.permitted? # => true
|
|
|
|
# copy_params = params.dup # => {"a"=>1}
|
|
|
|
# copy_params.permitted? # => true
|
2012-07-12 01:50:42 -04:00
|
|
|
def dup
|
|
|
|
super.tap do |duplicate|
|
2013-08-27 22:33:49 -04:00
|
|
|
duplicate.permitted = @permitted
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2013-08-27 22:33:49 -04:00
|
|
|
protected
|
|
|
|
def permitted=(new_permitted)
|
|
|
|
@permitted = new_permitted
|
|
|
|
end
|
|
|
|
|
2012-07-12 01:50:42 -04:00
|
|
|
private
|
2014-07-25 16:23:38 -04:00
|
|
|
def new_instance_with_inherited_permitted_status(hash)
|
|
|
|
self.class.new(hash).tap do |new_instance|
|
|
|
|
new_instance.permitted = @permitted
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2013-12-21 07:41:46 -05:00
|
|
|
def convert_hashes_to_parameters(key, value, assign_if_converted=true)
|
2014-06-07 07:04:40 -04:00
|
|
|
converted = convert_value_to_parameters(value)
|
2013-12-21 07:41:46 -05:00
|
|
|
self[key] = converted if assign_if_converted && !converted.equal?(value)
|
2013-12-20 19:11:47 -05:00
|
|
|
converted
|
|
|
|
end
|
|
|
|
|
2014-06-07 07:04:40 -04:00
|
|
|
def convert_value_to_parameters(value)
|
|
|
|
if value.is_a?(Array) && !converted_arrays.member?(value)
|
|
|
|
converted = value.map { |_| convert_value_to_parameters(_) }
|
|
|
|
converted_arrays << converted
|
2013-12-21 08:22:08 -05:00
|
|
|
converted
|
2013-12-20 19:11:47 -05:00
|
|
|
elsif value.is_a?(Parameters) || !value.is_a?(Hash)
|
2012-07-12 01:50:42 -04:00
|
|
|
value
|
|
|
|
else
|
2013-12-20 19:11:47 -05:00
|
|
|
self.class.new(value)
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def each_element(object)
|
|
|
|
if object.is_a?(Array)
|
|
|
|
object.map { |el| yield el }.compact
|
2013-09-22 10:57:21 -04:00
|
|
|
elsif fields_for_style?(object)
|
2012-09-01 03:30:07 -04:00
|
|
|
hash = object.class.new
|
|
|
|
object.each { |k,v| hash[k] = yield v }
|
|
|
|
hash
|
2012-07-12 01:50:42 -04:00
|
|
|
else
|
|
|
|
yield object
|
|
|
|
end
|
|
|
|
end
|
2013-01-19 12:32:27 -05:00
|
|
|
|
2013-09-22 10:57:21 -04:00
|
|
|
def fields_for_style?(object)
|
|
|
|
object.is_a?(Hash) && object.all? { |k, v| k =~ /\A-?\d+\z/ && v.is_a?(Hash) }
|
|
|
|
end
|
|
|
|
|
2013-01-19 12:32:27 -05:00
|
|
|
def unpermitted_parameters!(params)
|
|
|
|
unpermitted_keys = unpermitted_keys(params)
|
|
|
|
if unpermitted_keys.any?
|
|
|
|
case self.class.action_on_unpermitted_parameters
|
|
|
|
when :log
|
2013-03-07 04:41:05 -05:00
|
|
|
name = "unpermitted_parameters.action_controller"
|
|
|
|
ActiveSupport::Notifications.instrument(name, keys: unpermitted_keys)
|
2013-01-19 12:32:27 -05:00
|
|
|
when :raise
|
|
|
|
raise ActionController::UnpermittedParameters.new(unpermitted_keys)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def unpermitted_keys(params)
|
2014-06-27 02:01:30 -04:00
|
|
|
self.keys - params.keys - self.always_permitted_parameters
|
2013-01-19 12:32:27 -05:00
|
|
|
end
|
2013-01-20 11:59:53 -05:00
|
|
|
|
|
|
|
#
|
|
|
|
# --- Filtering ----------------------------------------------------------
|
|
|
|
#
|
|
|
|
|
|
|
|
# This is a white list of permitted scalar types that includes the ones
|
|
|
|
# supported in XML and JSON requests.
|
|
|
|
#
|
|
|
|
# This list is in particular used to filter ordinary requests, String goes
|
|
|
|
# as first element to quickly short-circuit the common case.
|
|
|
|
#
|
|
|
|
# If you modify this collection please update the API of +permit+ above.
|
|
|
|
PERMITTED_SCALAR_TYPES = [
|
|
|
|
String,
|
|
|
|
Symbol,
|
|
|
|
NilClass,
|
|
|
|
Numeric,
|
|
|
|
TrueClass,
|
|
|
|
FalseClass,
|
|
|
|
Date,
|
|
|
|
Time,
|
|
|
|
# DateTimes are Dates, we document the type but avoid the redundant check.
|
|
|
|
StringIO,
|
|
|
|
IO,
|
2013-01-23 17:14:47 -05:00
|
|
|
ActionDispatch::Http::UploadedFile,
|
2013-02-21 09:00:26 -05:00
|
|
|
Rack::Test::UploadedFile,
|
2013-01-20 11:59:53 -05:00
|
|
|
]
|
|
|
|
|
|
|
|
def permitted_scalar?(value)
|
|
|
|
PERMITTED_SCALAR_TYPES.any? {|type| value.is_a?(type)}
|
|
|
|
end
|
|
|
|
|
|
|
|
def permitted_scalar_filter(params, key)
|
|
|
|
if has_key?(key) && permitted_scalar?(self[key])
|
|
|
|
params[key] = self[key]
|
|
|
|
end
|
|
|
|
|
2013-01-20 19:09:31 -05:00
|
|
|
keys.grep(/\A#{Regexp.escape(key)}\(\d+[if]?\)\z/) do |k|
|
2013-01-20 12:32:02 -05:00
|
|
|
if permitted_scalar?(self[k])
|
|
|
|
params[k] = self[k]
|
2013-01-20 11:59:53 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def array_of_permitted_scalars?(value)
|
|
|
|
if value.is_a?(Array)
|
|
|
|
value.all? {|element| permitted_scalar?(element)}
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def array_of_permitted_scalars_filter(params, key)
|
|
|
|
if has_key?(key) && array_of_permitted_scalars?(self[key])
|
|
|
|
params[key] = self[key]
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2013-01-22 05:17:27 -05:00
|
|
|
EMPTY_ARRAY = []
|
2013-01-20 11:59:53 -05:00
|
|
|
def hash_filter(params, filter)
|
|
|
|
filter = filter.with_indifferent_access
|
|
|
|
|
|
|
|
# Slicing filters out non-declared keys.
|
|
|
|
slice(*filter.keys).each do |key, value|
|
2013-09-07 08:16:45 -04:00
|
|
|
next unless value
|
2013-01-20 11:59:53 -05:00
|
|
|
|
2013-01-22 05:17:27 -05:00
|
|
|
if filter[key] == EMPTY_ARRAY
|
2013-01-20 18:58:24 -05:00
|
|
|
# Declaration { comment_ids: [] }.
|
2013-01-20 11:59:53 -05:00
|
|
|
array_of_permitted_scalars_filter(params, key)
|
|
|
|
else
|
2013-03-24 09:35:41 -04:00
|
|
|
# Declaration { user: :name } or { user: [:name, :age, { address: ... }] }.
|
2013-01-20 11:59:53 -05:00
|
|
|
params[key] = each_element(value) do |element|
|
|
|
|
if element.is_a?(Hash)
|
|
|
|
element = self.class.new(element) unless element.respond_to?(:permit)
|
|
|
|
element.permit(*Array.wrap(filter[key]))
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
|
2012-09-22 00:27:40 -04:00
|
|
|
# == Strong \Parameters
|
2012-09-19 23:33:50 -04:00
|
|
|
#
|
2012-09-20 12:24:53 -04:00
|
|
|
# It provides an interface for protecting attributes from end-user
|
2012-10-18 02:38:36 -04:00
|
|
|
# assignment. This makes Action Controller parameters forbidden
|
2012-09-20 12:24:53 -04:00
|
|
|
# to be used in Active Model mass assignment until they have been
|
2012-09-19 23:33:50 -04:00
|
|
|
# whitelisted.
|
|
|
|
#
|
|
|
|
# In addition, parameters can be marked as required and flow through a
|
|
|
|
# predefined raise/rescue flow to end up as a 400 Bad Request with no
|
|
|
|
# effort.
|
|
|
|
#
|
|
|
|
# class PeopleController < ActionController::Base
|
2012-09-20 12:24:53 -04:00
|
|
|
# # Using "Person.create(params[:person])" would raise an
|
|
|
|
# # ActiveModel::ForbiddenAttributes exception because it'd
|
|
|
|
# # be using mass assignment without an explicit permit step.
|
|
|
|
# # This is the recommended form:
|
2012-09-19 23:33:50 -04:00
|
|
|
# def create
|
2012-09-20 12:24:53 -04:00
|
|
|
# Person.create(person_params)
|
2012-09-19 23:33:50 -04:00
|
|
|
# end
|
|
|
|
#
|
|
|
|
# # This will pass with flying colors as long as there's a person key in the
|
2012-09-21 21:10:57 -04:00
|
|
|
# # parameters, otherwise it'll raise an ActionController::MissingParameter
|
2012-09-19 23:33:50 -04:00
|
|
|
# # exception, which will get caught by ActionController::Base and turned
|
2012-09-21 21:10:57 -04:00
|
|
|
# # into a 400 Bad Request reply.
|
2012-09-19 23:33:50 -04:00
|
|
|
# def update
|
|
|
|
# redirect_to current_account.people.find(params[:id]).tap { |person|
|
2013-01-02 16:16:24 -05:00
|
|
|
# person.update!(person_params)
|
2012-09-19 23:33:50 -04:00
|
|
|
# }
|
|
|
|
# end
|
|
|
|
#
|
|
|
|
# private
|
|
|
|
# # Using a private method to encapsulate the permissible parameters is
|
2012-10-18 02:38:36 -04:00
|
|
|
# # just a good pattern since you'll be able to reuse the same permit
|
2012-09-19 23:33:50 -04:00
|
|
|
# # list between create and update. Also, you can specialize this method
|
|
|
|
# # with per-user checking of permissible attributes.
|
|
|
|
# def person_params
|
|
|
|
# params.require(:person).permit(:name, :age)
|
|
|
|
# end
|
|
|
|
# end
|
|
|
|
#
|
2014-03-30 22:19:30 -04:00
|
|
|
# In order to use <tt>accepts_nested_attributes_for</tt> with Strong \Parameters, you
|
2012-10-18 13:44:28 -04:00
|
|
|
# will need to specify which nested attributes should be whitelisted.
|
|
|
|
#
|
|
|
|
# class Person
|
|
|
|
# has_many :pets
|
|
|
|
# accepts_nested_attributes_for :pets
|
|
|
|
# end
|
|
|
|
#
|
|
|
|
# class PeopleController < ActionController::Base
|
|
|
|
# def create
|
|
|
|
# Person.create(person_params)
|
|
|
|
# end
|
|
|
|
#
|
|
|
|
# ...
|
|
|
|
#
|
|
|
|
# private
|
|
|
|
#
|
|
|
|
# def person_params
|
|
|
|
# # It's mandatory to specify the nested attributes that should be whitelisted.
|
|
|
|
# # If you use `permit` with just the key that points to the nested attributes hash,
|
|
|
|
# # it will return an empty hash.
|
2012-10-21 12:49:51 -04:00
|
|
|
# params.require(:person).permit(:name, :age, pets_attributes: [ :name, :category ])
|
2012-10-18 13:44:28 -04:00
|
|
|
# end
|
|
|
|
# end
|
|
|
|
#
|
2012-09-19 23:33:50 -04:00
|
|
|
# See ActionController::Parameters.require and ActionController::Parameters.permit
|
|
|
|
# for more information.
|
2012-07-12 01:50:42 -04:00
|
|
|
module StrongParameters
|
|
|
|
extend ActiveSupport::Concern
|
|
|
|
include ActiveSupport::Rescuable
|
|
|
|
|
2012-09-19 23:33:50 -04:00
|
|
|
# Returns a new ActionController::Parameters object that
|
|
|
|
# has been instantiated with the <tt>request.parameters</tt>.
|
2012-07-12 01:50:42 -04:00
|
|
|
def params
|
|
|
|
@_params ||= Parameters.new(request.parameters)
|
|
|
|
end
|
|
|
|
|
2012-09-19 23:33:50 -04:00
|
|
|
# Assigns the given +value+ to the +params+ hash. If +value+
|
|
|
|
# is a Hash, this will create an ActionController::Parameters
|
|
|
|
# object that has been instantiated with the given +value+ hash.
|
|
|
|
def params=(value)
|
|
|
|
@_params = value.is_a?(Hash) ? Parameters.new(value) : value
|
2012-07-12 01:50:42 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|