3

所以这看起来很简单,我有一个如下所示的控制器操作:

class Admin::UsersController < Admin::BaseController
...
def update_password
  @user = User.find(params[:user][:id])
  @user.password = params[:user][:password]
  if @user.save!
    Notifier.admin_password_change(@user).deliver
    flash[:success] = "Password Changed!"
    redirect_to edit_admin_user_path(@user)
  else
    render "edit"
  end
end
end

它似乎从来没有工作过。我需要在这里更高级的东西吗?这是我在 rails 控制台中看到的内容:

Started PUT "/admin/users/update_password" for 127.0.0.1 at 2013-07-15 10:01:50 -0600
Processing by Admin::UsersController#update_password as HTML
  Parameters: {"utf8"=>"✓", "authenticity_token"=>"ipedx2MJDZTQct6I4FUObrzDpMNl3pQWNVr9Ez7bDVc=", "user"=>{"id"=>"226", "password"=>"[FILTERED]", "password_confirmation"=>"[FILTERED]"}, "commit"=>"Change Password"}
  (6.8ms)  ALTER SESSION SET EDITION = EPACT_REDESIGN
  User Load (8.4ms)  SELECT "CRED_APP_USERS".* FROM "CRED_APP_USERS" WHERE "CRED_APP_USERS"."ID_NUMBER" = 10040 AND ROWNUM <= 1
  CodeModel Load (9.1ms)  SELECT "CRED_CODES".* FROM "CRED_CODES" WHERE (table_name = 'CRED_VEHICLES' OR table_name = 'CRED_FLEET')
  User Load (3.6ms)  SELECT "CRED_APP_USERS".* FROM "CRED_APP_USERS" WHERE "CRED_APP_USERS"."ID_NUMBER" = :a1 AND ROWNUM <= 1  [["id_number", "226"]]
  (3.3ms)  UPDATE "CRED_APP_USERS" SET "ENCRYPTED_PASSWORD" = 'ENCRYPTED PASSWORD STRING', "MODIFY_DT" = TO_DATE('2013-07-15 16:01:50','YYYY-MM-DD HH24:MI:SS') WHERE "CRED_APP_USERS"."ID_NUMBER" = 226
 Rendered notifier/admin_password_change.erb (0.1ms)

Sent mail to random@person.com (22ms)
...

我在这里做错了什么?电子邮件在控制台中打印出来,:success屏幕顶部出现闪光灯,但密码没有更改。

4

1 回答 1

3

不能说我明白为什么,但我需要设置 a password_reset_token,然后它就起作用了。这是该方法现在的样子:

def update_password
  @user = User.find(params[:user][:id])
  @user.reset_password_token = 'temp'
  @user.save!
  if @user.reset_password!(params[:user][:password], params[:user][:password_confirmation])
    Notifier.admin_password_change(@user).deliver
    flash[:success] = "Password Changed!"
    redirect_to edit_admin_user_path(@user)
  else
    render "edit"
  end
end

reset_password!当方法运行时,令牌会被吹走。我在文档中找不到任何暗示需要 a 的内容reset_password_token,但似乎是必需的。我不会说这段代码很漂亮,但解决方案有效。如果其他人想出更好的东西,我会改变我的答案。

于 2013-07-15T17:10:10.977 回答