diff options
author | elijah <elijah@riseup.net> | 2013-07-03 11:21:04 -0700 |
---|---|---|
committer | elijah <elijah@riseup.net> | 2013-07-04 04:12:59 -0700 |
commit | 33f55eed348769e1d14b283ec36b8f1bfc2d3c98 (patch) | |
tree | 9bed3d9ad625102e61773cca406d5868de187a34 /help/app/models/ticket.rb | |
parent | 01bba1b43129340d01132234f0cc7d673dbd6a5c (diff) |
fixed security vulnerability with ticket searching
Diffstat (limited to 'help/app/models/ticket.rb')
-rw-r--r-- | help/app/models/ticket.rb | 5 |
1 files changed, 1 insertions, 4 deletions
diff --git a/help/app/models/ticket.rb b/help/app/models/ticket.rb index 09bc64d..8066d0d 100644 --- a/help/app/models/ticket.rb +++ b/help/app/models/ticket.rb @@ -35,10 +35,7 @@ class Ticket < CouchRest::Model::Base validates :title, :presence => true validates :email, :allow_blank => true, :format => /\A([^@\s]+)@((?:[-a-z0-9]+\.)+[a-z]{2,})\Z/ - def self.for_user(user, options = {}, is_admin = false) - options[:user_id] = user.id - options[:is_admin] = is_admin - + def self.search(options = {}) @selection = TicketSelection.new(options) @selection.tickets end |