From dbca2c0fd8efc523f38631db4eeaa9b9d5fd1853 Mon Sep 17 00:00:00 2001 From: Sebastian Serth Date: Mon, 2 Oct 2023 17:35:54 +0200 Subject: [PATCH] Improve study_group_params to disallow ID and reformat --- app/controllers/study_groups_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/study_groups_controller.rb b/app/controllers/study_groups_controller.rb index 632e1717..904b7f2c 100644 --- a/app/controllers/study_groups_controller.rb +++ b/app/controllers/study_groups_controller.rb @@ -33,7 +33,7 @@ class StudyGroupsController < ApplicationController end def study_group_params - params[:study_group].permit(:id, :name, study_group_membership_ids: []) if params[:study_group].present? + params.require(:study_group).permit(:name, study_group_membership_ids: []) end private :study_group_params