Calling send or public_send with a params-derived method name lets attackers invoke arbitrary methods.
Whitelist allowed method names before dispatching with send.