Tuesday, September 30, 2008

initialize + super

Here's a word of caution to those using inheritance and calling super in the initialize method. Consider this:

def initialize(name, price)
super
@name = name
@price = price
end

Which parent method does it call? I was surprised to find out that without () after super, it automatically calls the initialize in the parent that has the parameters (name, price), rather than the one without parameters. If your intention was to call the parent's initialize without parameters, than you must do:

super()


W

Monday, September 29, 2008

TinyMCE: enforce maxlength

TinyMce doesn't have support for maxlength, and putting maxlength in the textfield tag won't do anything either.

If you try to google for a solution, you might come across this site

Don't waste your time on it, because the solution is built with the old tinymce api, it wouldn't work. Instead, use the solution from this post.


J

RoR: attr_accessible with attachment_fu

If you try to use attr_accessible on any model with attachment_fu plugin,
you'll get an error.

This article explains why


J

Sunday, September 28, 2008

RoR: attr_accessible

In a previous post, I talked about mass assignment. Well, there's something I discovered recently. If you have a polymorphic relationship, your model will have two columns: taggable_type and taggable_id. If you want to make these available for mass assignment, you cannot do:

attr_accessible taggable_type, taggable_id

Instead, RoR treats them like one attribute like so:

attr_accessible taggable


W

Saturday, September 27, 2008

RoR Generate + SVN

We all know about RoR's ability to generate controllers, models, migrations, etc. However, if you're using a repository, you have to manually add these newly created files. This could be a pain in the ass!

Here's a tip. If you're using SVN, you'll love this. Simply add the flag --svn and the generator will automatically add the newly created files to SVN. Simple!


W

Thursday, September 25, 2008

RoR: Mass Assignment Security

In RoR, it is possible to do something called mass assignments. For instance, when submitting a form, all the parameters are put into a params hash so you can do the following:

Product.create(params[:product])
product.update_attributes(params[:product])

Very simple, but by default, there is a security flaw. That flaw is covered in this post. If you are concerned about this, the easiest way would be to make it so that all your models will require attr_accessible on any attributes that you want mass assignment for. This then protects any attributes not listed by default.

In your config files, preferably in your initializers folder, add the following to protect all attributes:

ActiveRecord::Base.send(:attr_accessible, nil)

Then go through each model and think about which attributes should be exposed to mass assignments. For those that are not accessible, you must do the following to assign values:

product.store_id = store.id

This makes the assignment explicit and cannot be manipulated by the users.

Now that you know, go secure your applications!


W

Tuesday, September 23, 2008

Stack and Queue Implementation

Array in Ruby already has built in push and pop function you can use, but if you want to make it more strict and idiot proof, here's how you can implement it.

class Stack

def initialize
@stack = []
end

def push(x)
@stack.push(x)
end

def pop
@stack.pop unless is_empty?
end

def peek
@stack.last
end

def is_empty?
@stack.empty?
end

end

class Queue

def initialize
@queue = []
end

def enqueue(x)
@queue << x
end

def dequeue(x)
@queue.shift
end

def peek
@queue.first
end

def is_empty?
@queue.empty?
end

end


J