提交 4d478857 编写于 作者: A Aaron Patterson

Merge branch '2-3-later' into 2-3-stable

* 2-3-later:
  adding test for CVE
......@@ -920,6 +920,18 @@ def test_mass_assignment_protection_against_class_attribute_writers
end
end
def test_firm_safe_assign
firm = Company.new
assert_raise(ActiveRecord::UnknownAttributeError) do
firm.attributes = { "rating=\n" => 5 }
end
assert_equal 1, firm.rating
firm.attributes = { "rating(1)\n" => 5 }
assert_equal 1, firm.rating
end
def test_customized_primary_key_remains_protected
subscriber = Subscriber.new(:nick => 'webster123', :name => 'nice try')
assert_nil subscriber.id
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册