improve user password reset

This commit is contained in:
Alex Turchyn
2025-09-05 21:48:22 +03:00
committed by Pete Matsyburka
parent aeea619059
commit f7be74eb73
9 changed files with 110 additions and 12 deletions
+4
View File
@@ -1,6 +1,10 @@
# frozen_string_literal: true
class PasswordsController < Devise::PasswordsController
# rubocop:disable Rails/LexicallyScopedActionFilter
skip_before_action :require_no_authentication, only: %i[edit update]
# rubocop:enable Rails/LexicallyScopedActionFilter
class Current < ActiveSupport::CurrentAttributes
attribute :user
end
+2 -2
View File
@@ -16,7 +16,7 @@ class ProfileController < ApplicationController
end
def update_password
if current_user.update(password_params)
if current_user.update_with_password(password_params)
bypass_sign_in(current_user)
redirect_to settings_profile_index_path, notice: I18n.t('password_has_been_changed')
else
@@ -31,6 +31,6 @@ class ProfileController < ApplicationController
end
def password_params
params.require(:user).permit(:password, :password_confirmation)
params.require(:user).permit(:password, :password_confirmation, :current_password)
end
end
+8 -1
View File
@@ -1,7 +1,7 @@
# frozen_string_literal: true
class UsersController < ApplicationController
load_and_authorize_resource :user, only: %i[index edit update destroy]
load_and_authorize_resource :user, only: %i[index edit update destroy resend_reset_password]
before_action :build_user, only: %i[new create]
authorize_resource :user, only: %i[new create]
@@ -71,6 +71,13 @@ class UsersController < ApplicationController
redirect_back fallback_location: settings_users_path, notice: I18n.t('user_has_been_removed')
end
def resend_reset_password
current_user.send_reset_password_instructions
redirect_back fallback_location: settings_users_path,
notice: I18n.t('you_will_receive_an_email_with_password_reset_instructions_in_a_few_minutes')
end
private
def role_valid?(role)