Salt field对所有用户都是零

时间:2011-12-10 17:36:53

标签: ruby-on-rails-3

(ruby 1.9.2,rails 3.1)遵循Michael Hartl的教程。花了一天多时间试图找出问题,重新阅读本章,浏览SO,到目前为止还没有解决方案。 当我创建用户时,他们都是在DB中的盐场中使用nil创建的。像那样:

=> #<User id: 19, name: "John Doe Fourth", email: "jdoe4@ibm.com", created_at: "2011-12-10 16:36:09", updated_at: "2011-
12-10 16:36:09", encrypted_password: "5534438b422e928e80479756608b87d33881b5196a28be230c2...", salt: nil>

这是(imho)我尝试登录时收到“无效用户/电子邮件组合”的原因。

任何指针都会非常感激。

以下是您可能需要的信息,希望它不是太多。

users_controller.rb

def new
    @user = User.new
    @title = "Sign up"
  end

  def create
    @user = User.new(params[:user])
    if @user.save
            sign_in @user
            flash[:success] = "Welcome to the Blue Bird Microblog!"
            redirect_to @user
      else
      @title = "Sign up"
      render 'new'
    end
  end

user.rb

require 'digest' class User < ActiveRecord::Base

attr_accessible :name, :email, :password, :password_confirmation
attr_accessor :password, :salt

 before_save :encrypt_password

 def has_password?(submitted_password)
    encrypted_password == encrypt(submitted_password)   
 end

 def self.authenticate(email, submitted_password)
     user = find_by_email(email)
     puts user.inspect
     return nil  if user.nil?
     return user if user.has_password?(submitted_password)   
 end

  def self.authenticate_with_salt(id, cookie_salt)
     user = find_by_id(id)
     (user && user.salt == cookie_salt) ? user : nil   
  end

 private

 def encrypt_password 
       self.salt = make_salt unless has_password?(password)
       self.encrypted_password = encrypt(password) 
     end

  def encrypt(string)
       secure_hash("#{salt}--#{string}")
     end

     def make_salt
       secure_hash("#{Time.now.utc}--#{password}")
     end

     def secure_hash(string)
       Digest::SHA2.hexdigest(string)
     end

1 个答案:

答案 0 :(得分:2)

您需要删除

attr_accessor :salt

attr_accessor是例如变量,因为salt在数据库中;你需要摆脱它的访问线。