From bb227271fe686953df04ebe65fdc992ed85cddc7 Mon Sep 17 00:00:00 2001 From: bohung Date: Mon, 24 Oct 2022 16:30:14 +0800 Subject: [PATCH] Fix vulnerable. --- app/controllers/faqs_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/faqs_controller.rb b/app/controllers/faqs_controller.rb index 0195aac..ebac98e 100644 --- a/app/controllers/faqs_controller.rb +++ b/app/controllers/faqs_controller.rb @@ -35,7 +35,7 @@ class FaqsController < ApplicationController def show params = OrbitHelper.params - faq = Qa.can_display.find_by_param(params[:uid]) + faq = Qa.can_display.find_by_param(params[:uid].to_s) url_to_edit = OrbitHelper.user_can_edit?(faq) ? "/admin/faqs/#{faq.id.to_s}/edit" : ""