On Dec 14, 2010, at 10:09 PM, umuro wrote: > If forgery protection is disabled that a guest user can post and > create any objects on your Hobo site. I had to disable forgery > protection on a site to provide an XML API to my Hobo site easily and > quicly.
As I noted in the ticket, you'll really want to activate the :login_required filter on controller actions that aren't accessible to Guest users. That said, it does appear that this commit: https://github.com/tablatom/hobo/commit/e2976ee734d47bf0968f96e168b2cacd2393e55e changed the behavior of hobo_create very slightly - the old code used user_update_attributes, which had save *inside* a with_acting_user block which triggered the create permission check on new records. The new code was missing that, so I've added it to the correct places in master / 1-0-stable / rails3. --Matt Jones -- You received this message because you are subscribed to the Google Groups "Hobo Users" group. To post to this group, send email to [email protected]. To unsubscribe from this group, send email to [email protected]. For more options, visit this group at http://groups.google.com/group/hobousers?hl=en.
