Skip to content

Conversation

tarcieri
Copy link
Contributor

Before ALL functioned as a blanket method whitelist.

This constrains which methods are allowed to the ones in Rails::Auth::ACL::Resource::HTTP_METHODS

Before ALL functioned as a blanked method whitelist.

This constrains which methods are allowed to the ones in
Rails::Auth::ACL::Resource::HTTP_METHODS
@csstaub
Copy link

csstaub commented Apr 28, 2016

LGTM

@tarcieri tarcieri merged commit 12ab070 into master Apr 28, 2016
@tarcieri tarcieri deleted the tarcieri/use-whitelisted-methods-for-all branch April 28, 2016 23:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants