ruby-on-rails - BCrypt 身份验证总是失败 RAILS

标签 ruby-on-rails ruby bcrypt

我正在学习 Michael Hartl 的 Ruby on Rails 教程,在那里我到达了第 8 章。但是 authenticated? 方法总是返回 false。 :remember_token 的 Cookie 已正确保存。但是当我通过 BCrypt::Password.new(remember_digest).is_password?(remember_token) 比较数据库中消化的 remember_digest 时,它将始终返回 false。我正在使用 Rails 4.2.5.1。这是我的代码:

controllers/sessions_controller.rb

class SessionsController < ApplicationController
    def new
    end

    def create
        user = User.find_by(email: params[:session][:email].downcase)
        if user && user.authenticate(params[:session][:password])
            log_in(user)
            params[:session][:remember_me] == '1' ? remember(user) : forget(user)
            redirect_to user
        else
            flash.now[:danger] = 'Invalid email/password combination'
            render 'new'
        end
    end

    def destroy
        log_out if logged_in?
        redirect_to root_url
    end
end

models/user.rb

class User < ActiveRecord::Base
  attr_accessor :remember_token

    before_save { email.downcase! }
    validates :name, presence: true, length: { maximum: 50 }
    validates :email, presence: true, length: { maximum: 250 }, format: { with: /\A[\w+\-.]+@[a-z\d\-]+(\.[a-z\d\-]+)*\.[a-z]+\z/i }, uniqueness: { case_sensitive: false }
    validates :password, presence: true, length: { minimum: 6 }
    has_secure_password

    def self.digest(string)
        cost = ActiveModel::SecurePassword.min_cost ? BCrypt::Engine::MIN_COST : BCrypt::Engine.cost
        BCrypt::Password.create(string, cost: cost)
    end

    def User.new_token
      SecureRandom.urlsafe_base64
    end

    def remember
      self.remember_token = User.new_token
      update_attribute(:remember_digest, User.digest(remember_token))
    end

    def authenticated?(remember_token)
      return false if remember_digest.nil?
      BCrypt::Password.new(remember_digest).is_password?(remember_token)
    end

    def forget
      update_attribute(:remember_digest, nil)
    end
end

helpers/sessions_helper.rb

module SessionsHelper
    def log_in(user)
        session[:user_id] = user.id
    end

    def log_out
       forget(current_user)
        session.delete(:user_id)
        @current_user = nil
    end



    def remember(user)
        user.remember
        cookies.permanent.signed[:user_id] = user.id
        cookies.permanent.signed[:remember_token] = user.remember_token
    end

    def forget(user)
      user.forget
      cookies.delete(:user_id)
      cookies.delete(:remember_token)
    end

    def current_user
        if (user_id = session[:user_id])
            @current_user ||= User.find_by(id: user_id)
        elsif (user_id = cookies.signed[:user_id])
          user = User.find_by(id: user_id)
          if user && user.authenticated?(cookies[:remember_token])
            @current_user = user
            puts "INSIDE"
          end
        end
    end

    def logged_in?
        !current_user.nil?
    end
end

最佳答案

helpers/sessions_helper.rb => remember(user) 第二行更改:

cookies.permanent.signed[:remember_token] = user.remember_token

到:

cookies.permanent[:remember_token] = user.remember_token

关于ruby-on-rails - BCrypt 身份验证总是失败 RAILS,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/39018264/

相关文章:

ruby-on-rails - Rails - 获取与特定 wday 匹配的记录

ruby - 为什么 Ruby 1.9 lambda 调用不可能没有圆括号前面的点?

ruby - BCrypt 说很长,相似的密码是等价的 - 我的问题,gem 或密码学领域?

ruby-on-rails - Rails 3 在作用域中编写 IN 子句的最佳方式?

php - Bcrypt 比 md5 + salt 好在哪里?

node.js - Windows 上的 node-gyp 出现问题 : configure error

HTML 和 Ruby on Rails - 将 <br/> 标记显示为换行符,但将其他标记显示为字符串

ruby-on-rails - 将逻辑从 Controller 移动到 Rails 3 中的模型?

ruby-on-rails - 在模型中定义可以在 Controller 中访问的方法

ruby - SSL 模式标志 - 证书验证 : is it safe to use :none?