Fix information disclosure through Ransack

Closes #556

Merge request reports

Loading