]> git.openstreetmap.org Git - rails.git/blobdiff - app/controllers/user_roles_controller.rb
Sanitise parameters used in URL generation
[rails.git] / app / controllers / user_roles_controller.rb
index 1cfbaf977b0d5a487f2bba28bd198dc2cfa88c9b..9c0339c7a72c5f50825151df15a9a098512e201d 100644 (file)
@@ -15,7 +15,7 @@ class UserRolesController < ApplicationController
   end
 
   def revoke
-    UserRole.delete_all(:user_id => @this_user.id, :role => @role)
+    UserRole.where(:user_id => @this_user.id, :role => @role).delete_all
     redirect_to :controller => "user", :action => "view", :display_name => @this_user.display_name
   end