Spec-Zone.ru › Ruby on Rails 4.1

модуль ActionController::StrongParameters

Включенные модули:
ActiveSupport::Rescuable

Сильные параметры

Он предоставляет интерфейс для защиты атрибутов от назначения конечным пользователем. Это делает параметры Action Controller запрещёнными для использования в массовом назначении Active Model до тех пор, пока они не будут внесены в белый список.

Кроме того, параметры могут быть помечены как обязательные и проходить по предопределённому потоку raise/rescue, чтобы в конечном итоге стать ответом 400 Bad Request без усилий.

class PeopleController < ActionController::Base
  # Using "Person.create(params[:person])" would raise an
  # ActiveModel::ForbiddenAttributes exception because it'd
  # be using mass assignment without an explicit permit step.
  # This is the recommended form:
  def create
    Person.create(person_params)
  end

  # This will pass with flying colors as long as there's a person key in the
  # parameters, otherwise it'll raise an ActionController::MissingParameter
  # exception, which will get caught by ActionController::Base and turned
  # into a 400 Bad Request reply.
  def update
    redirect_to current_account.people.find(params[:id]).tap { |person|
      person.update!(person_params)
    }
  end

  private
    # Using a private method to encapsulate the permissible parameters is
    # just a good pattern since you'll be able to reuse the same permit
    # list between create and update. Also, you can specialize this method
    # with per-user checking of permissible attributes.
    def person_params
      params.require(:person).permit(:name, :age)
    end
end

Для использования accepts_nested_attributes_for с сильными параметрами, необходимо указать, какие вложенные атрибуты должны быть внесены в белый список.

class Person
  has_many :pets
  accepts_nested_attributes_for :pets
end

class PeopleController < ActionController::Base
  def create
    Person.create(person_params)
  end

  ...

  private

    def person_params
      # It's mandatory to specify the nested attributes that should be whitelisted.
      # If you use `permit` with just the key that points to the nested attributes hash,
      # it will return an empty hash.
      params.require(:person).permit(:name, :age, pets_attributes: [ :name, :category ])
    end
end

Для получения дополнительной информации см. ActionController::Parameters#require и ActionController::Parameters#permit.

Методы экземпляра публичного интерфейса

params() Показать исходный код

Возвращает новый объект ActionController::Parameters, который был создан с request.parameters.

# File actionpack/lib/action_controller/metal/strong_parameters.rb, line 543
def params
  @_params ||= Parameters.new(request.parameters)
end
params=(value) Показать исходный код

Присваивает заданный value в хеш params. Если value является хешем Hash, это создаст объект ActionController::Parameters, который был создан с заданным хешем value.

# File actionpack/lib/action_controller/metal/strong_parameters.rb, line 550
def params=(value)
  @_params = value.is_a?(Hash) ? Parameters.new(value) : value
end

© 2004–2016 David Heinemeier Hansson
Licensed under the MIT License.

Spec-Zone.ru

Настройки Оффлайн Что нового Помощь О нас
Spec-Zone .ru
спецификации, руководства, описания, API