Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I like this better than my solution, which was to specific which params were allowed for each controller action and remove any that weren't allowed.


Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: