def create
user = User.find_by_name(params[:name])
if user and user.authenticate(params[:password])
session[:user_id] = user.id
redirect_to admin_url
else
redirect_to login_url, alert: "Invalid user/password combination"
end
end
這裏爲什麼用戶被聲明爲局部變量而不是實例變量@user?爲什麼我們不在認證中使用@var?