2013-07-15 57 views
3

所以這看起來很簡單,我有一個控制器動作,看起來像這樣:設計:更改任何用戶密碼管理

class Admin::UsersController < Admin::BaseController 
... 
def update_password 
    @user = User.find(params[:user][:id]) 
    @user.password = params[:user][:password] 
    if @user.save! 
    Notifier.admin_password_change(@user).deliver 
    flash[:success] = "Password Changed!" 
    redirect_to edit_admin_user_path(@user) 
    else 
    render "edit" 
    end 
end 
end 

,它似乎永遠不會工作。我需要更高級的東西嗎?以下是我在滑軌控制檯中看到的內容:

Started PUT "/admin/users/update_password" for 127.0.0.1 at 2013-07-15 10:01:50 -0600 
Processing by Admin::UsersController#update_password as HTML 
    Parameters: {"utf8"=>"✓", "authenticity_token"=>"ipedx2MJDZTQct6I4FUObrzDpMNl3pQWNVr9Ez7bDVc=", "user"=>{"id"=>"226", "password"=>"[FILTERED]", "password_confirmation"=>"[FILTERED]"}, "commit"=>"Change Password"} 
    (6.8ms) ALTER SESSION SET EDITION = EPACT_REDESIGN 
    User Load (8.4ms) SELECT "CRED_APP_USERS".* FROM "CRED_APP_USERS" WHERE "CRED_APP_USERS"."ID_NUMBER" = 10040 AND ROWNUM <= 1 
    CodeModel Load (9.1ms) SELECT "CRED_CODES".* FROM "CRED_CODES" WHERE (table_name = 'CRED_VEHICLES' OR table_name = 'CRED_FLEET') 
    User Load (3.6ms) SELECT "CRED_APP_USERS".* FROM "CRED_APP_USERS" WHERE "CRED_APP_USERS"."ID_NUMBER" = :a1 AND ROWNUM <= 1 [["id_number", "226"]] 
    (3.3ms) UPDATE "CRED_APP_USERS" SET "ENCRYPTED_PASSWORD" = 'ENCRYPTED PASSWORD STRING', "MODIFY_DT" = TO_DATE('2013-07-15 16:01:50','YYYY-MM-DD HH24:MI:SS') WHERE "CRED_APP_USERS"."ID_NUMBER" = 226 
Rendered notifier/admin_password_change.erb (0.1ms) 

Sent mail to [email protected] (22ms) 
... 

我在做什麼錯在這裏?電子郵件在控制檯中打印出來,並且:success閃光燈出現在屏幕的頂部,但密碼未更改。

回答

3

不能說我明白爲什麼,但我需要設置一個password_reset_token,然後它就起作用了。下面就是該方法貌似現在:

def update_password 
    @user = User.find(params[:user][:id]) 
    @user.reset_password_token = 'temp' 
    @user.save! 
    if @user.reset_password!(params[:user][:password], params[:user][:password_confirmation]) 
    Notifier.admin_password_change(@user).deliver 
    flash[:success] = "Password Changed!" 
    redirect_to edit_admin_user_path(@user) 
    else 
    render "edit" 
    end 
end 

令牌獲取的交口稱讚reset_password!方法運行時。我找不到需要reset_password_token的文檔中的任何內容,但它似乎是必需的。我不會說這段代碼很漂亮,但是解決方案可行。如果別人想出更好的東西,我會改變我的答案。