Re: [Rails-core] Major security vulnerability!!!

2006-11-03 Thread Brian Hutchison
Do you mean 1.1.6?? http://weblog.rubyonrails.org/2006/8/10/rails-1-1-6-backports-and-full-disclosure On 8/10/06, Kent Sibilev <[EMAIL PROTECTED]> wrote: Hi,I think there is still a major vulnerability exists in the latest Rails 1.1.5.The problem is in the routing.rb file and safe_load_paths method

[Rails-core] ActiveResource

2006-11-03 Thread Rick Olson
I've been sitting on an ActiveResource patch for a few weeks, waiting to get some feedback from David. But, I see other folks like Jeremy are starting to use it, so I committed my patch: http://dev.rubyonrails.org/changeset/4890 It gets all the basic operations in working order, and adds suppor

[Rails-core] Rails AR/Oracle Unit Test: [4893] failed (getting worse)

2006-11-03 Thread Michael Schoen
"bitsweat" has kicked AR/Oracle while it was down... http://dev.rubyonrails.org/changeset/4893 r4893 | bitsweat | 2006-08-31 22:31:56 -0700 (Thu, 31 Aug 2006) | 1 line has_many :through conditions are sanitized by the associ

[Rails-core] Trac Triage with THE MAGGOT (Time To Clean Your Patches)

2006-11-03 Thread Zed Shaw
Evening, Alright folks, as Jeremy Kemper mentioned I'm working on a set of "triage" scripts for the Rails trac using RFuzz to go through all the tickets and clean them out. I've talked this over with the core guys, and they're behind it. I'm calling this set of scripts "THE MAGGOT" thanks to has