From 2c3381ae6d39ff59c98ed12eeb644f0abb7c210d Mon Sep 17 00:00:00 2001 From: Andrew Tomaka Date: Sun, 7 Apr 2013 06:14:15 -0400 Subject: [PATCH] Prevent user_id from being updated via form --- app/models/alert.rb | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/app/models/alert.rb b/app/models/alert.rb index 412a7a3..d63c031 100644 --- a/app/models/alert.rb +++ b/app/models/alert.rb @@ -1,5 +1,6 @@ class Alert < ActiveRecord::Base - attr_accessible :alerted, :course, :department, :user_id, :semester + attr_accessible :alerted, :course, :department, :semester + attr_protected :user_id validates :department, :presence => true, :length => {