Skip to content

Commit 2b2e4da

Browse files
author
Lee Richmond
committed
Always whitelist query params
1 parent 62ff7df commit 2b2e4da

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

lib/jsonapi_compliable/query.rb

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@ def self.default_hash
2424
def initialize(resource, params)
2525
@resource = resource
2626
@params = params
27+
@params = @params.permit! if @params.respond_to?(:permit!)
2728
end
2829

2930
# The relevant include directive

0 commit comments

Comments
 (0)