From 33f55eed348769e1d14b283ec36b8f1bfc2d3c98 Mon Sep 17 00:00:00 2001 From: elijah Date: Wed, 3 Jul 2013 11:21:04 -0700 Subject: fixed security vulnerability with ticket searching --- help/app/models/ticket.rb | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) (limited to 'help/app/models/ticket.rb') diff --git a/help/app/models/ticket.rb b/help/app/models/ticket.rb index 09bc64d..8066d0d 100644 --- a/help/app/models/ticket.rb +++ b/help/app/models/ticket.rb @@ -35,10 +35,7 @@ class Ticket < CouchRest::Model::Base validates :title, :presence => true validates :email, :allow_blank => true, :format => /\A([^@\s]+)@((?:[-a-z0-9]+\.)+[a-z]{2,})\Z/ - def self.for_user(user, options = {}, is_admin = false) - options[:user_id] = user.id - options[:is_admin] = is_admin - + def self.search(options = {}) @selection = TicketSelection.new(options) @selection.tickets end -- cgit v1.2.3