Skip to content

Commit 3b0823c

Browse files
authored
Security fix: remove role id from permitted params (#6117)
- removed role id from the permitted params in `create_user_params` in the `users_controller`. preventing the `role_id` injection highlighted in the security issue raised
1 parent b7f6a3a commit 3b0823c

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

app/controllers/api/v1/users_controller.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -163,7 +163,7 @@ def change_password
163163
private
164164

165165
def create_user_params
166-
@create_user_params ||= params.require(:user).permit(:name, :email, :password, :avatar, :language, :role_id, :invite_token)
166+
@create_user_params ||= params.require(:user).permit(:name, :email, :password, :avatar, :language, :invite_token)
167167
end
168168

169169
def update_user_params

0 commit comments

Comments
 (0)