Here's a word of caution to those using inheritance and calling super in the initialize method. Consider this:
def initialize(name, price)
super
@name = name
@price = price
end
Which parent method does it call? I was surprised to find out that without () after super, it automatically calls the initialize in the parent that has the parameters (name, price), rather than the one without parameters. If your intention was to call the parent's initialize without parameters, than you must do:
super()
W
Tuesday, September 30, 2008
Monday, September 29, 2008
TinyMCE: enforce maxlength
TinyMce doesn't have support for maxlength, and putting maxlength in the textfield tag won't do anything either.
If you try to google for a solution, you might come across this site
Don't waste your time on it, because the solution is built with the old tinymce api, it wouldn't work. Instead, use the solution from this post.
J
If you try to google for a solution, you might come across this site
Don't waste your time on it, because the solution is built with the old tinymce api, it wouldn't work. Instead, use the solution from this post.
J
RoR: attr_accessible with attachment_fu
If you try to use attr_accessible on any model with attachment_fu plugin,
you'll get an error.
This article explains why
J
you'll get an error.
This article explains why
J
Sunday, September 28, 2008
RoR: attr_accessible
In a previous post, I talked about mass assignment. Well, there's something I discovered recently. If you have a polymorphic relationship, your model will have two columns: taggable_type and taggable_id. If you want to make these available for mass assignment, you cannot do:
attr_accessible taggable_type, taggable_id
Instead, RoR treats them like one attribute like so:
attr_accessible taggable
W
attr_accessible taggable_type, taggable_id
Instead, RoR treats them like one attribute like so:
attr_accessible taggable
W
Saturday, September 27, 2008
RoR Generate + SVN
We all know about RoR's ability to generate controllers, models, migrations, etc. However, if you're using a repository, you have to manually add these newly created files. This could be a pain in the ass!
Here's a tip. If you're using SVN, you'll love this. Simply add the flag --svn and the generator will automatically add the newly created files to SVN. Simple!
W
Here's a tip. If you're using SVN, you'll love this. Simply add the flag --svn and the generator will automatically add the newly created files to SVN. Simple!
W
Thursday, September 25, 2008
RoR: Mass Assignment Security
In RoR, it is possible to do something called mass assignments. For instance, when submitting a form, all the parameters are put into a params hash so you can do the following:
Product.create(params[:product])
product.update_attributes(params[:product])
Very simple, but by default, there is a security flaw. That flaw is covered in this post. If you are concerned about this, the easiest way would be to make it so that all your models will require attr_accessible on any attributes that you want mass assignment for. This then protects any attributes not listed by default.
In your config files, preferably in your initializers folder, add the following to protect all attributes:
ActiveRecord::Base.send(:attr_accessible, nil)
Then go through each model and think about which attributes should be exposed to mass assignments. For those that are not accessible, you must do the following to assign values:
product.store_id = store.id
This makes the assignment explicit and cannot be manipulated by the users.
Now that you know, go secure your applications!
W
Product.create(params[:product])
product.update_attributes(params[:product])
Very simple, but by default, there is a security flaw. That flaw is covered in this post. If you are concerned about this, the easiest way would be to make it so that all your models will require attr_accessible on any attributes that you want mass assignment for. This then protects any attributes not listed by default.
In your config files, preferably in your initializers folder, add the following to protect all attributes:
ActiveRecord::Base.send(:attr_accessible, nil)
Then go through each model and think about which attributes should be exposed to mass assignments. For those that are not accessible, you must do the following to assign values:
product.store_id = store.id
This makes the assignment explicit and cannot be manipulated by the users.
Now that you know, go secure your applications!
W
Tuesday, September 23, 2008
Stack and Queue Implementation
Array in Ruby already has built in push and pop function you can use, but if you want to make it more strict and idiot proof, here's how you can implement it.
class Stack
def initialize
@stack = []
end
def push(x)
@stack.push(x)
end
def pop
@stack.pop unless is_empty?
end
def peek
@stack.last
end
def is_empty?
@stack.empty?
end
end
class Queue
def initialize
@queue = []
end
def enqueue(x)
@queue << x
end
def dequeue(x)
@queue.shift
end
def peek
@queue.first
end
def is_empty?
@queue.empty?
end
end
J
class Stack
def initialize
@stack = []
end
def push(x)
@stack.push(x)
end
def pop
@stack.pop unless is_empty?
end
def peek
@stack.last
end
def is_empty?
@stack.empty?
end
end
class Queue
def initialize
@queue = []
end
def enqueue(x)
@queue << x
end
def dequeue(x)
@queue.shift
end
def peek
@queue.first
end
def is_empty?
@queue.empty?
end
end
J
Subscribe to:
Posts (Atom)