You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rails 5中使用Devise Gem存储密码未加密问题求助

Troubleshooting Devise Saving Passwords as Plain Text in Rails

Hey there, fellow Rails beginner! I’ve been in your shoes before, so let’s break down why Devise might not be encrypting your passwords and how to fix it step by step.

First, let’s recap how Devise handles password encryption:
Devise relies on the bcrypt gem under the hood (you don’t need to handle bcrypt directly anymore!). The core magic happens with the :database_authenticatable module in your User model—this module automatically takes the plain-text password and password_confirmation parameters, hashes them using bcrypt, and stores the result in the encrypted_password column of your database. It never saves the plain text password if everything’s set up correctly.

Now let’s go through the most common issues that cause plain-text passwords:

1. Missing the :database_authenticatable module in your User model

This is the #1 culprit. Devise won’t encrypt passwords unless your model includes this essential module. Check your app/models/user.rb file—it should look something like this:

class User < ApplicationRecord
  # Include default devise modules. Others available are:
  # :confirmable, :lockable, :timeoutable, :trackable and :omniauthable
  devise :database_authenticatable, :registerable,
         :recoverable, :rememberable, :validatable
end

If :database_authenticatable is missing from that list, add it and restart your server. That module is responsible for all password encryption and authentication logic.

2. Incorrect database table structure

Devise requires a specific column to store the encrypted password: encrypted_password (a string column with a minimum length of 60 characters). If you’re still using an old password_digest column from your previous bcrypt setup, or if you don’t have encrypted_password at all, Devise can’t store the hashed value.

To fix this:

  • Run a migration to add the encrypted_password column if it’s missing:
    rails generate migration AddEncryptedPasswordToUsers encrypted_password:string:index
    
  • Then run rails db:migrate to apply it.
  • If you have a leftover password or password_digest column, you can keep it (but Devise won’t use it), or remove it with another migration if you don’t need it anymore.

3. Custom controller code overriding Devise’s logic

If you’ve created a custom registration or user update controller, make sure you’re not manually setting the password field in a way that skips Devise’s encryption. For example, avoid code like this in your controller:

# ❌ Bad: This skips Devise's encryption logic
@user = User.new(params[:user])
@user.password = params[:user][:password]
@user.save

Instead, let Devise handle the parameter processing. If you’re using strong parameters, ensure you’re allowing :password and :password_confirmation (Devise will handle the encryption automatically when you call save):

# ✅ Good: Let Devise handle encryption
def user_params
  params.require(:user).permit(:email, :password, :password_confirmation, :remember_me)
end

Also, don’t ever try to set encrypted_password manually—let Devise manage that field entirely.

4. Misconfigured Devise initializer

Check your config/initializers/devise.rb file for any changes that might disable encryption. Look for these lines:

# This should be set to :bcrypt (default)
config.encryptor = :bcrypt

# Optional: A pepper adds extra security, but it's not required for basic encryption
# config.pepper = 'your_secret_pepper_here'

If config.encryptor is commented out or set to something other than :bcrypt, uncomment it and set it to :bcrypt, then restart your server.

5. Missing bcrypt gem

Devise depends on the bcrypt gem to handle hashing. Even though Devise’s gem dependencies usually include bcrypt, it’s worth double-checking your Gemfile to make sure gem 'bcrypt' is present. If it’s missing, add it, run bundle install, and restart your server.

Once you’ve checked all these points, try creating a new user through your app’s registration flow and check the encrypted_password column in your database—it should now have a long, random-looking hash instead of plain text.

内容的提问来源于stack exchange,提问作者Abdul Mukheem Shaik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:14:01