|
|
|
|
|
by MartinMond
5223 days ago
|
|
I agree with you, but even if this was a reaction to public outcry the real reason to be disturbed is that top-notch Ruby devs like the GitHub guys didn't use attr_accessible. I can't wrap my mind around that. That you have to use attr_accessible is known throughout the Rails community since "ever". Only toy apps don't use it. It's like saving passwords in plaintext, only arguably even worse. |
|