Simon Willison’s Weblog

Subscribe

Is your Rails application safe? (via) update_attributes(params[:foo]) in ActiveRecord is an anti-pattern.