Ruby on Rails联系表单提交报错:ActiveModel::ForbiddenAttributesError
解决Rails 5.2 + InheritedResources中Contact表单提交的ActiveModel::ForbiddenAttributesError错误
你遇到的ActiveModel::ForbiddenAttributesError是Rails的**强参数(Strong Parameters)**机制抛出的——它是Rails用来防止恶意提交未授权参数的安全机制。结合你用的InheritedResources gem来看,问题出在控制器没有显式声明哪些参数是允许用来创建Contact实例的,导致Rails拦截了请求。
下面分两种场景给你解决方案:
场景1:使用InheritedResources默认的create动作(没重写create方法)
只需要在ContactsController里添加一个permitted_params私有方法,告诉InheritedResources哪些参数是合法的:
class ContactsController < InheritedResources::Base def index end private # 这里替换成你Contact模型实际需要的字段,比如name、email、message等 def permitted_params params.permit(contact: [:name, :email, :message]) end end
场景2:自己重写了create动作
如果你的控制器里自定义了create方法,那必须在创建Contact实例时使用经过强参数过滤的参数,不能直接用params[:contact]:
class ContactsController < InheritedResources::Base def index end def create # 用过滤后的参数创建实例 @contact = Contact.new(contact_params) if @contact.save # 保存成功后的逻辑,比如跳转+提示 redirect_to contacts_path, notice: 'Contact submitted successfully!' else # 保存失败则返回表单页面 render :new end end private # 定义强参数过滤规则 def contact_params params.require(:contact).permit(:name, :email, :message) # 替换为实际字段 end end
简单说,Rails从4.0开始就用强参数替代了旧的attr_accessible,而InheritedResources不会自动帮你处理参数授权,必须手动声明允许的参数列表。只要按照上面的方式配置,就能解决这个500错误啦。
内容的提问来源于stack exchange,提问作者Felipe Marcon
相关产品推荐
相关产品推荐

