Skip to content

Ransack 4.0 allowlist be an optional config #1482

@gvkhna

Description

@gvkhna

This allowlist enforcement actually needs to be able to be turned off. I understand the security protections trying to be put in place by this change. But for many apps it's not even needed, internal only apps that aren't even internet accessible don't need additional any additional attention. I can understand default requiring this but a simple config of some kind to turn it off would be needed as well.

TLDR: This was a breaking change and instituted quite abruptly, and so everyone probably is just pinning to the older version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions