make always permitted parameters configurable #12682
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
originally submitted via rails/strong_parameters#174
Was getting errors related to 'format' not being allowed as a param. Having to permit 'format' everywhere is messy, but I wasn't sure about changing S.P. to always allow format for everyone, since it is a client-supplied param and there may be some valid reason to allow control over permittance of 'format' rather than always permitting it. It seemed that just allowing NEVER_UNPERMITTED_PARAMS to be modifiable would be the best idea, so I converted it into a configuration option, using fewer double negatives ("always_permitted_parameters"). Not sure if that works for everyone or not, so this is really just a conversation starter.