You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rails 4与Rails 5应用共享Session及Devise配置问询

Alright, let's walk through how to get your Rails 5 app pulling in the current_user from your Rails 4 Devise setup—since both are on the same domain, we can make this work with shared session cookies and aligned Devise configs. Here's the step-by-step breakdown:

1. Align Session Store Configs Across Both Apps

First, we need to make sure both apps use the same session cookie settings so they can read each other's session data.

  • In your Rails 5 app's config/initializers/session_store.rb, copy the exact session store setup from your Rails 4 app, and explicitly set the domain (this is crucial for cross-app cookie sharing):

    Rails.application.config.session_store :cookie_store, key: '_app_store', domain: '.yourdomain.com'
    

    Pro tip: If you're using subdomains (like app.yourdomain.com and admin.yourdomain.com), the leading dot on the domain ensures the cookie is shared across all subdomains. If both apps are on the exact same domain, you can omit the dot, but the dot approach is more flexible.

  • Critical Step: Both apps must use the same secret_key_base. Rails uses this to encrypt and decrypt session cookies—if they don't match, Rails 5 won't be able to parse the session data from Rails 4.

    • Grab the secret_key_base from your Rails 4 app's config/secrets.yml
    • In Rails 5, if you're using encrypted credentials, run rails credentials:edit and add the key there: secret_key_base: "your-rails-4-secret-key-base". If you're using secrets.yml still, paste it directly there.
2. Set Up Devise in Your Rails 5 App

You don't need to rebuild the entire auth flow (login, registration) in Rails 5—just configure Devise to recognize the existing session from Rails 4 and load the current_user.

2.1 Install Devise

Start by adding Devise to your Rails 5 app:

gem 'devise'
bundle install
rails generate devise:install

2.2 Create a User Model (Reuse Rails 4's User Table)

You need a User model in Rails 5 to map to your existing user data from Rails 4. Generate the model without creating a new database migration (since your users live in the Rails 4 database):

rails generate model User --skip-migration

Then open app/models/user.rb and make sure it includes the same Devise modules as your Rails 4 User model. For example:

class User < ApplicationRecord
  devise :database_authenticatable, :registerable,
         :recoverable, :rememberable, :validatable
  # Copy any associations or custom methods from your Rails 4 User model here too
end

Note: This assumes both apps share the same database (common for same-domain multi-app setups). If they don't, you'll need to adjust to fetch user data via an API from Rails 4—let me know if you need help with that edge case.

2.3 Sync Devise Session Config

In your Rails 5 app's config/initializers/devise.rb, update these settings to match your Rails 4 setup:

# Match the session key from your session_store.rb
config.session_key = '_app_store'

# Use the same secret key as Rails to decrypt sessions
config.secret_key = Rails.application.secrets.secret_key_base

2.4 Load current_user in Rails 5 Controllers

To make current_user available in your Rails 5 controllers and views, add the Devise authentication filter to your ApplicationController:

class ApplicationController < ActionController::Base
  protect_from_forgery with: :exception
  before_action :authenticate_user! # Enforces auth for all pages—remove if you only need current_user on specific pages
end

If you don't want to enforce authentication site-wide, you can manually load current_user like this (though using Devise's built-in method is cleaner):

def set_current_user
  if session["warden.user.user.key"].present?
    user_id = session["warden.user.user.key"][0][0]
    @current_user = User.find(user_id)
  end
end
3. Test It Out
  • Log into your Rails 4 app first—this sets the session cookie in your browser.
  • Navigate to your Rails 5 app, and in a controller or view, add <%= current_user.inspect %> to verify the user loads correctly.
  • If it's not working, check these common issues:
    1. Is the session cookie showing up in your browser's dev tools with the correct key (_app_store) and domain?
    2. Did you copy the exact secret_key_base from Rails 4 to Rails 5?
    3. Are both apps running on the same domain (including subdomains)?

If your apps use HTTPS, update the session store config to include secure and SameSite settings to comply with modern browser standards:

Rails.application.config.session_store :cookie_store, key: '_app_store', domain: '.yourdomain.com', secure: true, same_site: :lax

内容的提问来源于stack exchange,提问作者Adam Young

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:05:36