lib/action_view/renderer/renderer.rb in actionview-4.2.5.1 vs lib/action_view/renderer/renderer.rb in actionview-4.2.5.2
- old
+ new
@@ -15,9 +15,13 @@
@lookup_context = lookup_context
end
# Main render entry point shared by AV and AC.
def render(context, options)
+ if options.respond_to?(:permitted?) && !options.permitted?
+ raise ArgumentError, "render parameters are not permitted"
+ end
+
if options.key?(:partial)
render_partial(context, options)
else
render_template(context, options)
end