diff --git a/app/controllers/principal_memberships_controller.rb b/app/controllers/principal_memberships_controller.rb index d4f4ba2de..e7a82d5f7 100644 --- a/app/controllers/principal_memberships_controller.rb +++ b/app/controllers/principal_memberships_controller.rb @@ -45,7 +45,7 @@ class PrincipalMembershipsController < ApplicationController end def update - @membership.attributes = params[:membership] + @membership.attributes = params.require(:membership).permit(:role_ids => []) @membership.save respond_to do |format| format.html { redirect_to_principal @principal }