<?xml version="1.0" encoding="UTF-8"?>
<commit>
  <added type="array"/>
  <modified type="array">
    <modified>
      <diff>@@ -5,6 +5,8 @@ class Comment &lt; ActiveRecord::Base
   before_save :auto_approve
   before_save :apply_filter
     
+  attr_accessible :author, :author_email, :author_url, :filter_id, :content
+  
   def self.per_page
     50
   end</diff>
      <filename>app/models/comment.rb</filename>
    </modified>
    <modified>
      <diff>@@ -35,4 +35,18 @@ class CommentTest &lt; Test::Unit::TestCase
       {:controller =&gt; &quot;admin/comments&quot;, :action =&gt; &quot;index&quot;, :format =&gt; 'csv', :page_id =&gt; &quot;6&quot;}
   end
   
+  def test_not_allowing_update_of_protected_attribs
+    @comment = Comment.create(
+      :author       =&gt; &quot;Evil Approve&quot;,
+      :author_email  =&gt; &quot;foo@bar.com&quot;,
+      :author_url  =&gt; &quot;http://www.test.com/&quot;,
+      :content     =&gt; &quot;Comment approved?&quot;,
+      :approved_at =&gt; Time.now,
+      :approved_by =&gt; 1
+      );
+    @comment = Comment.find_by_author('Evil Approve')
+    assert_nil(@comment.approved_at)
+    assert_nil(@comment.approved_by)
+  end
+  
 end</diff>
      <filename>test/unit/comment_test.rb</filename>
    </modified>
  </modified>
  <removed type="array"/>
  <parents type="array">
    <parent>
      <id>1439aaaee7106ee3f6d24471e43ff6a06b777e28</id>
    </parent>
  </parents>
  <author>
    <name>Martin Sadler</name>
    <email>mtsbtt@googlemail.com</email>
  </author>
  <url>http://github.com/ntalbott/radiant-comments/commit/f4c1921c39ffc15f61657015fcda71f32aaaa4fd</url>
  <id>f4c1921c39ffc15f61657015fcda71f32aaaa4fd</id>
  <committed-date>2008-10-08T01:46:14-07:00</committed-date>
  <authored-date>2008-10-08T01:46:14-07:00</authored-date>
  <message>security fix: protect from mass assignment</message>
  <tree>590519cf25fafa7f5b712bbda011700b20cfa22b</tree>
  <committer>
    <name>Martin Sadler</name>
    <email>mtsbtt@googlemail.com</email>
  </committer>
</commit>
