Use permit in StripeAccountsController

This commit is contained in:
Matt-Yorkley
2021-02-18 11:12:36 +00:00
parent 1535c680f5
commit a8009d044b

View File

@@ -3,7 +3,7 @@ require 'stripe/account_connector'
module Admin
class StripeAccountsController < Spree::Admin::BaseController
def connect
payload = raw_params.slice(:enterprise_id)
payload = params.permit(:enterprise_id)
key = Openfoodnetwork::Application.config.secret_token
url_params = { state: JWT.encode(payload, key, 'HS256'), scope: "read_write" }
redirect_to Stripe::OAuth.authorize_url(url_params)