You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用devise-token-auth在注册与登录响应中隐藏用户ID

Remove id field from devise-token-auth registration/login responses

Environment

  • Ruby 2.7.5
  • Rails 6.1.6.1
  • devise 4.8.1
  • devise_token_auth 1.2.0

Problem

When using devise-token-auth for user registration and login, I want to exclude the id field from the API response. Here's the current vs desired output:

Current Response

{ "status": "success", "data": { "id": 1, "provider": "email", "uid": "test@example.com", "allow_password_change": false, "name": null, "email": "test@example.com", "created_at": "2022-08-14T08:20:24.396Z", "updated_at": "2022-08-14T08:20:24.453Z" } }

Desired Response

{ "status": "success", "data": { "provider": "email", "uid": "test@example.com", "allow_password_change": false, "name": null, "email": "test@example.com", "created_at": "2022-08-14T08:20:24.396Z", "updated_at": "2022-08-14T08:20:24.453Z" } }

Solution

There are two clean, maintainable ways to achieve this, depending on your project's setup:

devise-token-auth relies on ActiveModel Serializers by default, so creating a custom serializer lets you explicitly control which fields get returned:

  1. Generate the serializer file in your terminal:
rails generate serializer User
  1. Open app/serializers/user_serializer.rb and define only the fields you want to include (omit :id entirely):
class UserSerializer < ActiveModel::Serializer
  attributes :provider, :uid, :allow_password_change, :name, :email, :created_at, :updated_at
end
  1. Update your User model to use this custom serializer. Edit app/models/user.rb:
class User < ApplicationRecord
  # Existing devise/devise_token_auth configuration...
  include DeviseTokenAuth::Concerns::User

  def active_model_serializer
    UserSerializer
  end
end

After making these changes, registration and login responses will automatically exclude the id field. This approach is great if you might need to adjust response fields later—it keeps all field logic in one place.

Option 2: Override Controller Render Methods

If you don't use ActiveModel Serializers or prefer a more direct approach, override the success render methods in custom controller subclasses:

  1. Create custom controllers for registrations and sessions:
# app/controllers/custom_registrations_controller.rb
class CustomRegistrationsController < DeviseTokenAuth::RegistrationsController
  private

  def render_create_success
    render json: {
      status: 'success',
      data: resource.as_json(except: [:id])
    }
  end
end

# app/controllers/custom_sessions_controller.rb
class CustomSessionsController < DeviseTokenAuth::SessionsController
  private

  def render_login_success
    render json: {
      status: 'success',
      data: resource.as_json(except: [:id])
    }
  end
end
  1. Update your routes to use these custom controllers in config/routes.rb:
mount_devise_token_auth_for 'User', at: 'auth', controllers: {
  registrations: 'custom_registrations',
  sessions: 'custom_sessions'
}

Both methods work reliably, but the serializer approach is more scalable for long-term maintenance.

内容的提问来源于stack exchange,提问作者tari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 18:24:10