RailsDM 2019 ã§ã®çºè¡¨è³æã§ã
RailsDM 2019 ã§ã®çºè¡¨è³æã§ã
ãä¸è©±ã«ãªãã¾ããããã³ãã¨ã³ãæ å½ããã¦ããå°åæ£å¤§ã§ããWebãã¼ã¸ã®è¡¨ç¤ºãç£è¦ãã¦å·®ç°ããã£ãå ´åãã©ã®ãã¼ã¸ã§è¡¨ç¤ºã®å¤åãèµ·ãã¦ããããç¥ããã¨ãåºæ¥ãããã°ã©ã ãå®è£ ããã®ã§ãã®ãã¨ã«ã¤ãã¦æ¸ããã¨æãã¾ãã ä½ã«ã¤ãã£ãã®ï¼ åãããã³ãã¨ã³ããæ å½ãã¦ãããµã¼ãã¹ãæçãµããªãã§å¤§è¦æ¨¡ãªããã³ãã¨ã³ãã³ã¼ãã®ãªãã¡ã¯ã¿ãªã³ã°è¡ãéã«è¡¨ç¤ºãã¹ããèªååããããã«ä½æãã¾ããããæçãµããªãã¯PCã»ã¹ããåããã¦å¤§ä½350-400ãã¼ã¸ã®è¡¨ç¤ºãã¿ã¼ã³ãåå¨ããæ¯è¼çè¦æ¨¡ã®å¤§ãããµã¤ãã§ããå ¨ãã¼ã¸ã«å½±é¿ãä¸ãããããªä½æ¥ã¯å¤§è¦æ¨¡ãªååã¨ãªããä»åã®ãªãã¡ã¯ã¿ãªã³ã°ã§ã¯è¡¨ç¤ºãã¹ãã®è¨ç»ãªã©ã®æ®µåããå¿ è¦ã§ãããå¾æ¥ã®äººæã«ããQAã§ã¯ç´°ãããã°ãè¦éããããæéããããå¹çãæªãã®ã§ãå¯è½ãªéãèªååãããã¨èãå®è£ ãã¾ããã å®è£ ã®æ¦è¦ ãã®ç£è¦ã®ã·ã¹ãã ã¯ä»¥ä¸ã®ï¼ã¤å®è£ ãçµåã
Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? æ¦è¦ Webã¢ããªã±ã¼ã·ã§ã³ã«ã¦ããªã½ã¼ã¹ã®ä¸é¨æ´æ°ãè¡ãéãã©ã®ããã«URLè¨è¨ãè¡ãã¨ã·ã³ãã«ã§ç¾ãããï¼æ¬å½ã¯ããã¾ã§èãã¦ããªãã£ããã©ï¼æ©ãã§ããã¨ããã @t_wada ããããç´ æµãªè¨è¨æéããæ示ããã ãã¾ããã æ¬è¨äºã¯ãã®å 容ã«å ãã¦ãå®éã«èªåã§è¡ã£ããã¨ã調ã¹ããã¨ãæã£ãäºãªã©ãã¾ã¨ãã¦ããã¾ãã ãããã æ°é±éåã«SIãã©ããããããã¢ãªããã³ã¸ã¼ã決ãã¦Webã®ä¸çã«é£ã³è¾¼ãã ç§ã¯ãå°ããªå°ããªWebã¢ããªã±ã¼ã·ã§ã³ãrails newããææ¢ãã§ä½ã£ã¦ãã¾ããã ãããªã¨ããç°¡åãªãªã½ã¼ã¹ã®ä¸é¨æ´æ°æ©è½
Hashã§ãããã¼ã ã®äººã¨å¼ã°ãã¦ããææã俺ã«ãããã¾ãããç¾å¨ãæ ªå¼ä¼ç¤¾ã¸ã¢ãã£ã¼ã§ã¨ã³ã¸ãã¢ããã£ã¦ã¾ããå ¬ç§ã¨ãã«idã§å¼ã°ããæ¬åãå¿ããã¡ãªã®ãæè¿ã®æ©ã¿ã§ãããå¥ã«æ©ãã§ãã¾ããã ã¸ã¢ãã£ã¼ã®ã¨ã³ã¸ãã¢ã¯5人ã§ãåºæ¬çã«ã¾ãã¹ããªãä»äºããããã®ã®ããç¨åº¦å¾æä¸å¾æããã£ã¦ãåã¯ã¤ã³ãã©ã¨ããããµã¼ãã®ä¸è©±ããããã¨ãå¤ãã§ãï¼è«¸è¬ã®äºæ ã«ããååºã«ã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹ã¨ã³ã¸ãã¢ã¨è¨è¼ããã¦ããã®ã§ããâ¦ï¼ã ããã§ä»åã¯ãã¸ã¢ãã£ã¼ãæ¯ããæè¡ãã¨é¡ãã¦ãã¸ã¢ãã£ã¼ã®ä½¿ã£ã¦ããæè¡ããã£ããç´¹ä»ãããã¨æãã¾ããã¾ãã¿ã¤ãã«ä½¿ãããã£ãã ããããæããã¾ãã Rails3 Ruby on Rails 3ã§Webã¢ããªã±ã¼ã·ã§ã³ãéçºãã¦ãã¾ãã ã¦ã§ããµã¼ãã¹ã¨ãã¦è¦ãã¨ãã¸ã¢ãã£ã¼ã¯ããã°ä»é¢¨ã®ãæ²ç¤ºæ¿ãã§ãããªããã¼ãªä½ãã¯å°ãªãããRailsã¨ã®ç¸æ§ã¯è¯ãã®ã§ã¯ãªã
Github ã«èå¼±æ§ããã£ã人㯠Rails ã«æããã¡ãªèå¼±æ§ã issue ã«æãã¦ãããç¸æã«ããããå®éã«ãããçªãã¦ãããä¸è¦ childish ã ããããã ãç°¡åã«èå¼±ãªå®è£ ããªããã¦ãã¾ãã¨ãããã¨ã ãé±æãã®ä»æ¥ãRubyist ã¯ã¾ãé¢é£æ å ±ã«ä¸èªãã â Yuki Nishijima (@yuki24) March 4, 2012 æ°ã«ãªã£ã¦èª¿ã¹ãã®ã§ã¡ã¢ãèªåãæ°ãã¤ããªãã¨ãªã¼ã Public Key Security Vulnerability and Mitigation - github.com/blog/ github ã«èå¼±æ§ããã£ã¦ãããçªããããããã Rails ã¢ããªã«ãããã¡ãªèå¼±æ§ã®ä¸ã¤ãMass assignment ã¨ãããã¿ã¤ãã®èå¼±æ§ã§ããã mass assignment èå¼±æ§ã¨ã¯ mass assignment èå¼±æ§ã¨ã¯ä½ãã
This guide describes common security problems in web applications and how to avoid them with Rails. After reading this guide, you will know: How to use the built-in authentication generator. All countermeasures that are highlighted. The concept of sessions in Rails, what to put in there and popular attack methods. How just visiting a site can be a security problem (with CSRF). What you have to pay
å æ¥ã®ããã¯ãããã«ã½ã³ã§åºä¼ã£ã wantedly ãä½ã£ã¦ã仲ããã ã¨è¨ã£ã¦ãã®ã§ãé¢ç½ãããªã®ã§ wantedly ãéããã¦ã¿ã¾ããã wantedly ã¡ãªã¿ã«ãã¼ã¿ãæ°ç¾ä¸ãªã¼ãã¼ããªããããªã®ã«ãã©ã®ãã¼ã¸ããã°ã¤ã³ããã¨2-5ç§ãããããã£ã¦ããã®ã§ã確å®ã«éãã§ãããã ãªãã¨ããæè¦ã¯ããåããããã¾ããã ã¢ããªã±ã¼ã·ã§ã³ãµã¤ãã®ãã¥ã¼ãã³ã° åå¿è *1ã«ãããã¡ãªåé¡ã¨ã㦠SQL ã«é©åã«ã¤ã³ããã¯ã¹å¼µã£ã¦ãªã ãã£ãã·ã¥ãã¹ãå ´æããã£ãã·ã¥ãã¦ããªã ç¡é§ãªãã¼ã¿ãå¼ãããã¦ã ãã¨ãããããã¾ããã®ã§é ã«å®è£ ãè¦ã¦ããã¾ããã SQLã«é©åãªã¤ã³ããã¯ã¹ãå¼µã£ã¦ãªã å¼µã£ã¦ããã¾ããï¼ã³ã£ããï¼ï¼¼(^o^)ï¼ ãã£ãã·ã¥ãã¹ãå ´æããã£ãã·ã¥ãã¦ããªã Facebook API ãå©ç¨ããã¢ããªã±ã¼ã·ã§ã³ãªãã§ãããã¦ã¼ã¶ã®ãã¼ã¿ã®åå¾ãæ¯å馬鹿æ£ç´ã« HT
ãããè¦ã¦ããã£ã¦ã人ã«ããMongoDBã£ã¦ä½ãããã®ï¼ãã¨æ¹ãã¦èããã¦ãã¾ã£ã¦ãããããã£ãããããããã¨æ¸ãã¦ãªãã£ããªãã¨æã£ãã®ã§ããªãèªåãMongoDBã«èå³ãæã£ã¦ããã®ããã¨ãããã¨ãæ¸ãã¦ã¿ããããèªåã®æããæ¸ãã¦ã¿ããRailsä¸å¿ã®è©±ã«ãªã£ã¦ãã¾ã£ããã©ãã¢ãã³ãªãã¬ã¼ã ã¯ã¼ã¯ãªããããªã«è©±ã¯å¤ãããªãã®ããªãã¨æã£ã¦ããã ããããã®ãã£ããã¯ãããåå¹´éãããRuby on Rails(以ä¸RoR)ã§éçºãã¦ãããã¨ã«ããã ããåå¹´å¼±ã»ã©RoRã§éçºããã¦ããããªãã«æºè¶³ãã¦ããã®ã ãã©ãActiveRecordã«é¢ãã¦ã¯è²ã ã¨ã²ã£ãããã¨ããããã£ãã ãActiveRecordãRoRã®ç´ æ´ãããã¨ãããã®ãã®ã ãã¨è©ä¾¡ãã¦ãã人ãããããèªåã®ä¸ã§ã¯éã§ãActiveRecordã¯RoRã®ä¸ã§ãããªããã¾ãã¡ãªé¨åã ãããActiveRecordã¨
455ä¸äººã®ã¦ã¼ã¶ã¼ãæããä¸çã§ãææ°ãæ¥æ¬æ大ã®ã¬ã·ãã³ãã¥ããã£ã¼ãµã¤ããCOOKPADï¼ã¯ãã¯ãããï¼ãããããéå¶ããã®ããã¯ãã¯ãããã ãåãµã¤ãã¯ãä»å¹´10å¨å¹´ãè¿ãã7æã«ã¯å¤§è¦æ¨¡ãªãªãã¥ã¼ã¢ã«ãå®æ½ããã ãã®ãªãã¥ã¼ã¢ã«ã«ããã£ã¦ã¯ãRubyãæ¡ç¨ãæé2.8åPVã®å¤§è¦æ¨¡ãµã¤ããRuby on Railsã«ä¹ãã¦ãããRailsãµã¤ãã¨ãã¦ã¯ä¸çã§ãææ°ã®è¦æ¨¡ã ãã·ã¼ããããããã¯ã¼ã¯ã¹ ã¨ã³ã¿ã¼ãã©ã¤ãºã»ã¡ãã£ã¢ çµ±æ¬ å ¼ ZDNet Japanç·¨éé·ã®å¤§éããä»ãæ¥æ¬æ大ã®Railsãµã¤ãã¨ãªã£ãCOOKPADã®ä½é社é·ã«ããã®éå¶ã¨ä»å¾ã®è¨ç»ã«ã¤ãã¦èããã èãæï¼å¤§éæä¸ãæ§æï¼å¯æ°¸æåï¼ããã³ã½ã³ï¼ 大éï¼ ãããããä»åã®ãªãã¥ã¼ã¢ã«ã®çãã¯ã©ãã«ãã£ãã®ã§ãããã? ä½éæ°(以ä¸ãæ¬ç§°ç¥)ï¼ ä¸è¨ã§ããã°ãä»å¾ã®ä¸é·æçãªæé·ãæ³å®ãã¦ã®æ¹åãä¸çªã®ç®
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}