Fix vulnerable.

This commit is contained in:
BoHung Chiu 2022-10-24 16:19:51 +08:00
parent ee55f63fa8
commit 51a3909203
2 changed files with 3 additions and 3 deletions

View File

@ -14,7 +14,7 @@ class Admin::DiplomasController < OrbitMemberController
end end
def new def new
@member = MemberProfile.find_by(:uid=>params['uid']) rescue nil @member = MemberProfile.find_by(:uid=>params['uid'].to_s) rescue nil
@diploma = Diploma.new @diploma = Diploma.new
if params[:desktop] if params[:desktop]
@ -139,7 +139,7 @@ class Admin::DiplomasController < OrbitMemberController
end end
def frontend_setting def frontend_setting
@member = MemberProfile.find_by(:uid=>params['uid']) rescue nil @member = MemberProfile.find_by(:uid=>params['uid'].to_s) rescue nil
@intro = DiplomaIntro.find_by(:member_profile_id=>@member.id) rescue nil @intro = DiplomaIntro.find_by(:member_profile_id=>@member.id) rescue nil
@intro = @intro.nil? ? DiplomaIntro.new({:member_profile_id=>@member.id}) : @intro @intro = @intro.nil? ? DiplomaIntro.new({:member_profile_id=>@member.id}) : @intro
end end

View File

@ -58,7 +58,7 @@ class PersonalDiplomasController < ApplicationController
def show def show
params = OrbitHelper.params params = OrbitHelper.params
plugin = Diploma.where(:is_hidden=>false).find_by(uid: params[:uid]) plugin = Diploma.where(:is_hidden=>false).find_by(uid: params[:uid].to_s)
fields_to_show = [ fields_to_show = [
"name", "name",