【发布时间】:2015-08-31 04:21:42
【问题描述】:
我的应用中有一个包含一些嵌套字段的表单。
我正在使用simple_form_for、bootstrap、slim 和 Rails 4.2 以及here 所述的表单支持对象
这是服务器端缺少证明参数(注意,我检查了标记中的 authenticity_token 字段)
这是日志
Started POST "/example_sentences/9/breakdowns" for ::1 at 2015-08-31 12:37:57 +0900
ActiveRecord::SchemaMigration Load (18.8ms) SELECT "schema_migrations".* FROM "schema_migrations"
Processing by BreakdownsController#create as HTML
Parameters: {"example_sentence_id"=>"9"}
Can't verify CSRF token authenticity
关闭 CSRF 保护以尝试调试会得到以下结果:
Started POST "/example_sentences/9/breakdowns" for ::1 at 2015-08-31 13:00:05 +0900
Processing by BreakdownsController#create as HTML
Parameters: {"example_sentence_id"=>"9"}
User Load (24.1ms) SELECT "users".* FROM "users" WHERE "users"."id" = $1 ORDER BY "users"."id" ASC LIMIT 1 [["id", 1]]
Completed 400 Bad Request in 355ms (ActiveRecord: 156.3ms)
ActionController::ParameterMissing - param is missing or the value is empty: breakdown:
显然,有很多因素表明这偏离了 Rails 的方式,因此任何数量的事情都可能出错。并且显示视图代码会引入更多问题。
所以,我将展示生成的 HTML(减去样式信息),并询问是否有人能看出这有什么明显的错误。我有点希望这将是一个面对面的时刻,并且遗漏了一些明显的东西。
<form novalidate="novalidate" id="new_breakdown" action="/example_sentences/9/breakdowns" accept-charset="UTF-8" method="post">
<input name="utf8" type="hidden" value="✓">
<input type="hidden" name="authenticity_token" value="cOU87EZXRkV1a0QA1ohwlqM5Ny43QvgcRaqKan9mdgs12jR8RnJfyVXp9VIJHkMRkBUvZ16Io7QaGcBazjVqGw==">
<input type="text" value="これ" name="breakdown[word_mapping][1][text]" id="breakdown_word_mapping_1_text" >
<input type="text" value="this" name="breakdown[word_mapping][1][translation]" id="breakdown_word_mapping_1_translation">
<input type="text" value="は" name="breakdown[word_mapping][2][text]" id="breakdown_word_mapping_2_text">
<input type="text" value="" name="breakdown[word_mapping][2][translation]" id="breakdown_word_mapping_2_translation">
<input type="submit" name="commit" value="Save translations">
</form>
其他信息
在 ~/.rbenv/versions/2.2.2/lib/ruby/gems/2.2.0/gems/actionpack-4.2.3/lib/action_controller/metal/request_forgery_protection.rb 中
在:valid_authenticity_token? 检查第 277 行期间
对于 request.body.read 我可以看到真实性令牌 “UTF8 =%E2%9C%93&authenticity_token = RTFWCJZ3QnRgnNWFF66ej2aetx7H5n7BcbLKW4v145YADl6YllJb%2BEAeZNfIOK0IVbKvV64sJWkuAYBrOqb%2Fhg%3D%3D&击穿%5Bword_mapping%5D%5B1%5D%5Btext%5D =%E3%81%93%E3%82%8C&击穿%5Bword_mapping%5D%5B1 %5D%5Btranslation%5D=this&breakdown%5Bword_mapping%5D%5B1%5D%5Breading%5D=&breakdown%5Bword_mapping%5D%5B1%5D%5B_destroy%5D=0&breakdown%5Bword_mapping%5D%5B2%5D%5Btext%5D=% E3%81%AF&breakdown%5Bword_mapping%5D%5B2%5D%5Btranslation%5D=&breakdown%5Bword_mapping%5D%5B2%5D%5Breading%5D=&breakdown%5Bword_mapping%5D%5B2%5D%5B_destroy%5D=0&breakdown%5Bword_mapping% 5D%5B3%5D%5Btext%5D=%E3%83%9A%E3%83%B3&breakdown%5Bword_mapping%5D%5B3%5D%5Btranslation%5D=pen&breakdown%5Bword_mapping%5D%5B3%5D%5Breading%5D=&breakdown %5Bword_mapping%5D%5B3%5D%5B_destroy%5D=0&breakdown%5Bword_mapping%5D%5B4%5D%5Btext%5D=%E3%81%A7%E3%81%99&breakdown%5Bword_mapping%5D%5B4%5D%5Btranslation% 5D=&breakdown%5Bword_mapping%5D%5B4%5D%5Breading%5D=&breakdown%5Bword_mapping%5D%5B4%5D%5B_destroy%5D=0&br eakdown%5Bword_mapping%5D%5B%5D%5Btext%5D=%E3%81%93%E3%82%8C&breakdown%5Bword_mapping%5D%5B%5D%5Btranslation%5D=&breakdown%5Bword_mapping%5D%5B%5D%5Breading %5D=&breakdown%5Bword_mapping%5D%5B%5D%5B_destroy%5D=0&breakdown%5Bword_mapping%5D%5B%5D%5Btext%5D=%E3%81%AF&breakdown%5Bword_mapping%5D%5B%5D%5Btranslation%5D= &breakdown%5Bword_mapping%5D%5B%5D%5Breading%5D=&breakdown%5Bword_mapping%5D%5B%5D%5B_destroy%5D=0&breakdown%5Bword_mapping%5D%5B%5D%5Btext%5D=%E3%83%9A%E3 %83%B3&breakdown%5Bword_mapping%5D%5B%5D%5Btranslation%5D=&breakdown%5Bword_mapping%5D%5B%5D%5Breading%5D=&breakdown%5Bword_mapping%5D%5B%5D%5B_destroy%5D=0&breakdown%5Bword_mapping%5D %5B%5D%5Btext%5D=%E3%81%A7%E3%81%99&breakdown%5Bword_mapping%5D%5B%5D%5Btranslation%5D=&breakdown%5Bword_mapping%5D%5B%5D%5Breading%5D=&breakdown% 5Bword_mapping%5D%5B%5D%5B_destroy%5D=0&commit=Save+translations"
但是encoded_masked_token的值是nil
事实上,path_parameters 是我在请求中获得的参数的唯一部分。
in: "~/.rbenv/versions/2.2.2/lib/ruby/gems/2.2.0/gems/actionpack-4.2.3/lib/action_dispatch/http/request.rb"
(byebug) pp @env.keys.sort.grep(/action_dispatch/).grep(/param/).map{|k| [k, @env[k]]}
[["action_dispatch.parameter_filter", [:password]],
["action_dispatch.request.parameters",
{"controller"=>"breakdowns",
"action"=>"create",
"example_sentence_id"=>"9"}],
["action_dispatch.request.path_parameters",
{:controller=>"breakdowns", :action=>"create", :example_sentence_id=>"9"}],
["action_dispatch.request.query_parameters", {}],
["action_dispatch.request.request_parameters", {}]]
所以我已经不知何故失去了参数。
【问题讨论】:
-
显示您的控制器代码
-
所以我想避免过多地讨论控制器或视图,因为参数本身甚至没有触及控制器。如您所见,我从 url 获得了 example_sentence_id 参数,但没有别的
标签: ruby-on-rails forms post params