Why don't we validate controller parameters?

How my one silly typo caused an avalanche of 500 errors (aka strong parameters are not enough to make RoR app secure enough)

