diff --git a/ruby/ql/src/queries/security/cwe-915/MassAssignment.qhelp b/ruby/ql/src/queries/security/cwe-915/MassAssignment.qhelp index 7a96cd49b049..289f3a6a6ec1 100644 --- a/ruby/ql/src/queries/security/cwe-915/MassAssignment.qhelp +++ b/ruby/ql/src/queries/security/cwe-915/MassAssignment.qhelp @@ -5,7 +5,7 @@

Operations that allow for mass assignment (setting multiple attributes of an object using a hash), such as ActiveRecord::Base.new, should take care not to - allow arbitrary parameters to be set by the user. Otherwise, unintended attributes may be set, such as an isAdmin feild for a User object. + allow arbitrary parameters to be set by the user. Otherwise, unintended attributes may be set, such as an is_admin field for a User object.

@@ -29,6 +29,6 @@ - +
  • Rails guides: Strong Parameters.