I\'m attempting to avoid any SQL injection vulnerabilities by substituting with my params on a join.
Category.joins(\"LEFT OUTER JOIN incomes ON incomes.cate
Try
Category.joins(:incomes).where(:incomes => { :dept_id => params[:Dept] })
And check out the Rails documentation for joining tables.