I'm an experienced developer, but not terribly familiar with Rails.
What do you mean "properly deploy their app"?
The sample code at rubyonrails.org looks like it has the same problem to me, i.e., it would be vulnerable if it were put into production in the right (entirely reasonable) circumstances.
What do you mean "properly deploy their app"?
The sample code at rubyonrails.org looks like it has the same problem to me, i.e., it would be vulnerable if it were put into production in the right (entirely reasonable) circumstances.