refusedViewModel compared only the top-level type with the controller's model. It now walks the type through pointers, slices, arrays, maps, struct fields and the results of exported methods, and the values held in interface-typed members, refusing the controller's model, any other GORM model (TableName, a gorm tag, gorm.Model, gorm.DeletedAt) and html/template's trusted content types anywhere in that structure.
13 KiB
13 KiB