From 1535c680f5420cb2b0848c2b8f5caa5a33c8e2fb Mon Sep 17 00:00:00 2001 From: Matt-Yorkley <9029026+Matt-Yorkley@users.noreply.github.com> Date: Sun, 10 Jan 2021 10:46:07 +0000 Subject: [PATCH] Fix direct params access in StripeAccountsController --- app/controllers/admin/stripe_accounts_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/admin/stripe_accounts_controller.rb b/app/controllers/admin/stripe_accounts_controller.rb index 90b4e2c85c..c4debf826b 100644 --- a/app/controllers/admin/stripe_accounts_controller.rb +++ b/app/controllers/admin/stripe_accounts_controller.rb @@ -3,7 +3,7 @@ require 'stripe/account_connector' module Admin class StripeAccountsController < Spree::Admin::BaseController def connect - payload = params.slice(:enterprise_id) + payload = raw_params.slice(:enterprise_id) key = Openfoodnetwork::Application.config.secret_token url_params = { state: JWT.encode(payload, key, 'HS256'), scope: "read_write" } redirect_to Stripe::OAuth.authorize_url(url_params)