lynndylanhurley / lynndylanhurley/devise_token_auth

Token should not be created if a user already has a token. Following is the create method of DeviseTokenAuth

Open
#1,556 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Ruby
Stars
3.6k
Forks
1.1k
PR merge metrics
No merged PRs in 30d

Description

 def create
   
    field = (resource_params.keys.map(&:to_sym) & resource_class.authentication_keys).first
    
    @resource = nil
    if field
      email_value = get_case_insensitive_field_from_resource_params(field)  
      @resource = find_resource(field, email_value)  
    end
    debugger # login is done
    if @resource && valid_params?(field, email_value) && @resource.active_for_authentication?
      
      valid_password = @resource.valid_password?(resource_params[:password])
      if (@resource.respond_to?(:valid_for_authentication?) && !@resource.valid_for_authentication? { valid_password }) || !valid_password
        return render_create_error_bad_credentials
      end
      debugger
      @token = @resource.create_token
      @resource.save
      sign_in(:user, @resource, store: false, bypass: false)    
    
      yield @resource if block_given?

      render_create_success
    elsif @resource && !(@resource.active_for_authentication?)
      if @resource.respond_to?(:locked_at) && @resource.locked_at
        render_create_error_account_locked
      else
        render_create_error_not_confirmed
      end
    else
      render_create_error_bad_credentials
    end
    
  end

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue points to DeviseTokenAuth’s create method; start by tracing @resource.create_token and @resource.save in that entry point. Check how an existing user token is represented and verify that signing in a user who already has a token does not create another token.

Written by the indexing model from the issue text.

Assessment

Tech stack
rails, ruby
Domain
api, authentication, backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.