lynndylanhurley / lynndylanhurley/devise_token_auth

Why session controller checked confirmation before validate the password?

Open
#1,506 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Ruby
Stars
3.6k
Forks
1.1k
PR merge metrics
No merged PRs in 30d

Description

```ruby
devise_token_auth (1.2.0)
devise (4.8.0)
```

```ruby
if @resource && valid_params?(field, q_value) && (!@resource.respond_to?(:active_for_authentication?) || @resource.active_for_authentication?)
valid_password = @resource.valid_password?(resource_params[:password])
if (@resource.respond_to?(:valid_for_authentication?) && !@resource.valid_for_authentication? { valid_password }) || !valid_password
return render_create_error_bad_credentials
end
@token = @resource.create_token
@resource.save

sign_in(:user, @resource, store: false, bypass: false)

yield @resource if block_given?

render_create_success
elsif @resource && !(!@resource.respond_to?(:active_for_authentication?) || @resource.active_for_authentication?)
if @resource.respond_to?(:locked_at) && @resource.locked_at
render_create_error_account_locked
else
render_create_error_not_confirmed
end
else
render_create_error_bad_credentials
end
```

Contributor guide

Open the contributing guide

Research direction

Start at the session controller entry point shown in the issue and reproduce the confirmation-versus-password-validation flow with devise_token_auth 1.2.0 and devise 4.8.0. Determine the expected authentication behavior and document or test the order that should be considered done.

Written by the indexing model from the issue text.

Assessment

Tech stack
rails, ruby
Domain
api, authentication
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.