chore: another fix

This commit is contained in:
Sojan
2025-03-12 01:59:05 -07:00
parent f1f10cea88
commit ec614e17a2
+9
View File
@@ -19,6 +19,11 @@ class InstallationConfig < ApplicationRecord
# https://discuss.rubyonrails.org/t/cve-2022-32224-possible-rce-escalation-bug-with-serialized-columns-in-active-record/81017
# FIX ME : fixes breakage of installation config. we need to migrate.
# Fix configuration in application.rb
#
# Note: This whole thing is because we store the installation config serialized in YAML in Database
# This serialized version stores HashWithIndifferentAccess, We could avoid all this complexity if we store the value as JSONB
# We could also avoid this issue if we migrate the installation config to JSONB
# We should do this migration at some point in time.
serialize :serialized_value, coder: YAML, type: ActiveSupport::HashWithIndifferentAccess
before_validation :set_lock
@@ -32,6 +37,10 @@ class InstallationConfig < ApplicationRecord
after_commit :clear_cache
def value
# This is an extra hack again cause of the YAML serialization, in case of new object initialization in super admin
# It was throwing error as the default value of column '{}' was failing in deserialization.
return {}.with_indifferent_access if new_record? && @attributes['serialized_value']&.value_before_type_cast == '{}'
serialized_value[:value]
end