9119: Use Oj strict mode for decoding JSON.
[arvados.git] / services / api / app / controllers / arvados / v1 / api_client_authorizations_controller.rb
index 83968be75262ae75a7f797945ae30cda527c6a31..5229d80b0c9ce530bcb62bebc4f8318a21c633e7 100644 (file)
@@ -15,7 +15,7 @@ class Arvados::V1::ApiClientAuthorizationsController < ApplicationController
       new(user_id: system_user.id,
           api_client_id: params[:api_client_id] || current_api_client.andand.id,
           created_by_ip_address: remote_ip,
-          scopes: Oj.load(params[:scopes] || '["all"]'))
+          scopes: Oj.strict_load(params[:scopes] || '["all"]'))
     @object.save!
     show
   end