On Dec 14, 2010, at 10:09 PM, umuro wrote:

> If forgery protection is disabled that a guest user can post and
> create any objects on your Hobo site. I had to disable forgery
> protection on a site to provide an XML API to my Hobo site easily and
> quicly.

As I noted in the ticket, you'll really want to activate the :login_required 
filter on controller actions that aren't accessible to Guest users.

That said, it does appear that this commit:

https://github.com/tablatom/hobo/commit/e2976ee734d47bf0968f96e168b2cacd2393e55e

changed the behavior of hobo_create very slightly - the old code used 
user_update_attributes, which had save *inside* a with_acting_user block which 
triggered the create permission check on new records. The new code was missing 
that, so I've added it to the correct places in master / 1-0-stable / rails3.

--Matt Jones

-- 
You received this message because you are subscribed to the Google Groups "Hobo 
Users" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/hobousers?hl=en.

Reply via email to