ruby-on-railsrubyrubygemsruntime-errorpsych

Ruby on Rails + Psych::DisallowedClass in PostsController#show


Never seen this error before. I wonder if it is about the RoR env setup than my codes.

btw why is it even "klassname", should it not be with c "classname"

enter image description here


My Gemfile

source 'https://rubygems.org'

ruby '2.7.1'

git_source(:github) do |repo_name|
  repo_name = "#{repo_name}/#{repo_name}" unless repo_name.include?("/")
  "https://github.com/#{repo_name}.git"
end

# gems I installed
gem 'aws-sdk-s3'
gem 'bootsnap', require: false
gem 'simple_form'
gem 'friendly_id', '~> 5.1.0'
gem 'devise'
gem 'will_paginate', '~> 3.1.0'
gem 'meta-tags'
gem 'omniauth'
gem "omniauth-rails_csrf_protection", "~> 1.0"
gem 'omniauth-twitter'
gem 'impressionist', '~>1.6.1'
gem 'gibbon'
gem 'acts_as_votable', '~> 0.11.1'
gem 'awesome_print'
gem 'sanitize'
gem "mini_magick"
gem "redcarpet"
gem 'file_validators'
gem 'pg_search'
gem 'invisible_captcha'
gem "recaptcha"

# Bundle edge Rails instead: gem 'rails', github: 'rails/rails'
gem 'rails', '~> 5.2'
# Use sqlite3 as the database for Active Record
gem 'pg'
# Use Puma as the app server
gem 'puma', '~> 3.7'
# Use SCSS for stylesheets
gem 'sass-rails', '~> 5.0'
# Use Uglifier as compressor for JavaScript assets
gem 'uglifier', '>= 1.3.0'
# See https://github.com/rails/execjs#readme for more supported runtimes
# gem 'therubyracer', platforms: :ruby

# Use CoffeeScript for .coffee assets and views
gem 'coffee-rails', '~> 4.2'
# Turbolinks makes navigating your web application faster. Read more: https://github.com/turbolinks/turbolinks
gem 'turbolinks', '~> 5'
# Build JSON APIs with ease. Read more: https://github.com/rails/jbuilder
gem 'jbuilder', '~> 2.5'
# Use Redis adapter to run Action Cable in production
# gem 'redis', '~> 3.0'
# Use ActiveModel has_secure_password
# gem 'bcrypt', '~> 3.1.7'

# Use Capistrano for deployment
# gem 'capistrano-rails', group: :development

group :development, :test do
  # Call 'byebug' anywhere in the code to stop execution and get a debugger console
  gem 'byebug', platforms: [:mri, :mingw, :x64_mingw]
  # Adds support for Capybara system testing and selenium driver
  gem 'capybara', '~> 2.13'
  gem 'selenium-webdriver'
end

group :development do
  # Access an IRB console on exception pages or by using <%= console %> anywhere in the code.
  gem 'web-console', '>= 3.3.0'
  gem 'listen', '>= 3.0.5', '< 3.2'
  # Spring speeds up development by keeping your application running in the background. Read more: https://github.com/rails/spring
  gem 'spring'
  gem 'spring-watcher-listen', '~> 2.0.0'
end

# Windows does not include zoneinfo files, so bundle the tzinfo-data gem
gem 'tzinfo-data', platforms: [:mingw, :mswin, :x64_mingw, :jruby]

gem 'mina'
gem 'elasticsearch-model'
gem 'elasticsearch-rails'

Solution

  • I think the issue is with Psych gem version.

    You can try adding this line application.rb

    config.active_record.yaml_column_permitted_classes = [Symbol, Hash, Array, ActiveSupport::HashWithIndifferentAccess]