#105 open
Wojciech Ochmański

Protect attributes not modified during the updates

Reported by Wojciech Ochmański | June 9th, 2009 @ 05:07 PM | in Release 3.2

Currently user is able to change activity owner, change the own role to admin.
Use: attr_protected, or attr_accessible

Comments and changes to this ticket

Please Sign in or create a free account to add a new ticket.

With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.

New-ticket Create new ticket

Create your profile

Help contribute to this project by taking a few moments to create your personal profile. Create your profile »

A Merb-based time tracking and invoicing system

You can update this ticket by sending an email to from your email client. (help)