From a8009d044ba48fd31d7833addfb3ab96b8634ded Mon Sep 17 00:00:00 2001 From: Matt-Yorkley <9029026+Matt-Yorkley@users.noreply.github.com> Date: Thu, 18 Feb 2021 11:12:36 +0000 Subject: [PATCH] Use permit in StripeAccountsController --- app/controllers/admin/stripe_accounts_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/admin/stripe_accounts_controller.rb b/app/controllers/admin/stripe_accounts_controller.rb index c4debf826b..c848714b80 100644 --- a/app/controllers/admin/stripe_accounts_controller.rb +++ b/app/controllers/admin/stripe_accounts_controller.rb @@ -3,7 +3,7 @@ require 'stripe/account_connector' module Admin class StripeAccountsController < Spree::Admin::BaseController def connect - payload = raw_params.slice(:enterprise_id) + payload = params.permit(:enterprise_id) key = Openfoodnetwork::Application.config.secret_token url_params = { state: JWT.encode(payload, key, 'HS256'), scope: "read_write" } redirect_to Stripe::OAuth.authorize_url(url_params)