Actions
Defect #28930
closed[Rails 5.2] sanitize dangerous query statements
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Code cleanup/refactoring
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Resolution:
Affected version:
Description
DEPRECATION WARNING: Dangerous query method (method whose arguments are used as raw SQL) called with non-attribute argument(s): "(CASE WHEN versions.effective_date IS NULL THEN 1 ELSE 0 END) DESC". Non-attribute arguments will be disallowed in Rails 6.0. This method should not be called with user-provided values, such as request parameters or model attributes. Known-safe values can be passed by wrapping them in Arel.sql().
Files
Related issues
Updated by Go MAEDA over 6 years ago
- Related to Patch #28933: Migrate to Rails 5.2 added
Actions