Mass assignment strategy update (not whitelisted by default). CRSF protection by default with authenticity_token. Secure encryption with bcrypt (password_digest). force_ssl method to ensure https. No more SQL Injections with ActiveRecord. And much more... jeudi, 15 novembre 12