【发布时间】:2014-09-27 13:20:21
【问题描述】:
我们正在尝试使用Devise Security Extension gem 来使用 :password_archivable 功能,以防止用户重复使用旧密码。每当我们尝试在网站上更改用户密码时,都会出现批量分配错误。
我们模型的一部分:
class User < Person
rolify
devise :database_authenticatable, #...
:password_archivable
#attr_accessible :encrypted_password, :password_salt
...
end
我们控制器的一部分:
class HealthPromotersController < ApplicationController
load_and_authorize_resource
...
def update
...
respond_to do |format|
if @health_promoter.update_attributes(params[:health_promoter])
sign_in(@health_promoter, :bypass => true) if @current_user.id == @health_promoter.id
format.html { redirect_to @health_promoter, notice: 'Health Promoter was successfully updated.' }
format.json { head :no_content }
else
format.html { render action: "edit" }
format.json { render json: @health_promoter.errors, status: :unprocessable_entity }
end
end
end
当我们进入编辑 health_promoter 页面并输入密码和 password_confirmation 时,当 password_archivable.rb 代码尝试设置时,Devise Security Extension 会失败并出现针对 encrypted_password 和 password_salt 的 Mass Assignment 错误:
OldPassword.new(old_password_params)
ActiveModel::MassAssignmentSecurity::Error at /health_promoters/1
Can't mass-assign protected attributes: encrypted_password, password_salt
我们尝试将 :encrypted_password 和 :password_salt 添加到 attr_accessible 列表中,但无济于事。设计文档(github.com/plataformatec/devise/blob/3d9dea39b2978e3168604ccda956fb6ec17c5e27/lib/devise/models/authenticatable.rb)说我们可以使用 :force_except 或 :except 但不清楚如何或在哪里指定。
我们使用以下版本: Ruby 2.0.0p451、Rails 3.2.19、Devise 3.2.4、Devise 安全扩展 0.8.0
任何帮助将不胜感激。
【问题讨论】:
-
你读过这个吗?不知道是不是同一个东西。 stackoverflow.com/questions/14334036/…
标签: ruby-on-rails ruby ruby-on-rails-3 devise mass-assignment