2013-06-22 99 views
1

创建新用户时,Authlogic似乎忽略了密码参数。这是我的users_controller类:Authlogic忽略密码参数

class Api::V1::UsersController < ApplicationController 

    def create 
    @user = User.new(user_params) 

    respond_to do |format| 
     if @user.save 
     format.json { render :json => @user, :status => :created} 
     else 
     format.json { render :json => @user.errors, :status => :unprocessable_entity } 
     end 
    end 
    end 

    private 
    def user_params 
    params.require(:user).permit(:username, :email, :password) 
    end 

end 

我的用户模型:

class User < ActiveRecord::Base 
    acts_as_authentic do |c| 
     c.require_password_confirmation = false 
    end 
end 

当我发送POST请求/ API/V1 /用户/同一个用户名,电子邮件地址和密码参数,authlogic说,即使不是,密码也不能为空。这里有什么用轨打印出来:

Started POST "/api/v1/users/" for 127.0.0.1 at 2013-06-22 00:03:30 -0400 
Processing by Api::V1::UsersController#create as */* 
    Parameters: {"email"=>"[email protected]", "password"=>"[FILTERED]", "username"=>"myUser", "user"=>{"username"=>"myUser", "email"=>"[email protected]"}} 
    (0.2ms) BEGIN 
    User Exists (0.4ms) SELECT 1 AS one FROM "users" WHERE LOWER("users"."email") = LOWER('[email protected]') LIMIT 1 
    User Exists (0.2ms) SELECT 1 AS one FROM "users" WHERE LOWER("users"."username") = LOWER('myUser') LIMIT 1 
    User Exists (0.3ms) SELECT 1 AS one FROM "users" WHERE "users"."persistence_token" = '7b72bab3627914d33e83e4efe1c5a9dab190750efb227698c8b5b6be7a7ccf118160d8e12623078543e0f4e5f31eb30828799cb0d97fb2af195daee894c79902' LIMIT 1 
    (0.2ms) ROLLBACK 
Completed 422 Unprocessable Entity in 33ms (Views: 0.2ms | ActiveRecord: 3.2ms) 

我使用的是最新的authlogic和Ruby 2/Rails的4

回答

3

在摘录看看从Rails日志:

{"email"=>"[email protected]", "password"=>"[FILTERED]", "username"=>"myUser", "user"=>{"username"=>"myUser", "email"=>"[email protected]"}} 

看起来你送稍有不妥参数。要被Authlogic识别,password参数应该在user密钥的参数哈希中。即从Rails的日志行看起来应该像这样(注意字符串的结尾):

{"email"=>"[email protected]", "password"=>"[FILTERED]", "username"=>"myUser", "user"=>{"username"=>"myUser", "email"=>"[email protected]", "password" => "[FILTERED]"}} 

要解决它,你可以这样做一个黑客:

private 
def user_params 
    params.require(:user).permit(:username, :email).merge(:password => :password) 
end 

或者,您也可以调整从客户端发送的参数(例如,在发送HTTP POST请求时,使用user[password]参数的名称而不是password)。

0

尝试了这一点: -

acts_as_authentic do |config| 
    config.check_passwords_against_database = false 
    config.validate_password_field = false 
    config.crypted_password_field = false 
end 
+0

这允许用户创建,但它没有密码。我需要我的用户有密码。 – edc1591