Rails 4与Rails 5应用共享Session及Devise配置问询
Alright, let's walk through how to get your Rails 5 app pulling in the current_user from your Rails 4 Devise setup—since both are on the same domain, we can make this work with shared session cookies and aligned Devise configs. Here's the step-by-step breakdown:
First, we need to make sure both apps use the same session cookie settings so they can read each other's session data.
In your Rails 5 app's
config/initializers/session_store.rb, copy the exact session store setup from your Rails 4 app, and explicitly set the domain (this is crucial for cross-app cookie sharing):Rails.application.config.session_store :cookie_store, key: '_app_store', domain: '.yourdomain.com'Pro tip: If you're using subdomains (like
app.yourdomain.comandadmin.yourdomain.com), the leading dot on the domain ensures the cookie is shared across all subdomains. If both apps are on the exact same domain, you can omit the dot, but the dot approach is more flexible.Critical Step: Both apps must use the same
secret_key_base. Rails uses this to encrypt and decrypt session cookies—if they don't match, Rails 5 won't be able to parse the session data from Rails 4.- Grab the
secret_key_basefrom your Rails 4 app'sconfig/secrets.yml - In Rails 5, if you're using encrypted credentials, run
rails credentials:editand add the key there:secret_key_base: "your-rails-4-secret-key-base". If you're usingsecrets.ymlstill, paste it directly there.
- Grab the
You don't need to rebuild the entire auth flow (login, registration) in Rails 5—just configure Devise to recognize the existing session from Rails 4 and load the current_user.
2.1 Install Devise
Start by adding Devise to your Rails 5 app:
gem 'devise' bundle install rails generate devise:install
2.2 Create a User Model (Reuse Rails 4's User Table)
You need a User model in Rails 5 to map to your existing user data from Rails 4. Generate the model without creating a new database migration (since your users live in the Rails 4 database):
rails generate model User --skip-migration
Then open app/models/user.rb and make sure it includes the same Devise modules as your Rails 4 User model. For example:
class User < ApplicationRecord devise :database_authenticatable, :registerable, :recoverable, :rememberable, :validatable # Copy any associations or custom methods from your Rails 4 User model here too end
Note: This assumes both apps share the same database (common for same-domain multi-app setups). If they don't, you'll need to adjust to fetch user data via an API from Rails 4—let me know if you need help with that edge case.
2.3 Sync Devise Session Config
In your Rails 5 app's config/initializers/devise.rb, update these settings to match your Rails 4 setup:
# Match the session key from your session_store.rb config.session_key = '_app_store' # Use the same secret key as Rails to decrypt sessions config.secret_key = Rails.application.secrets.secret_key_base
2.4 Load current_user in Rails 5 Controllers
To make current_user available in your Rails 5 controllers and views, add the Devise authentication filter to your ApplicationController:
class ApplicationController < ActionController::Base protect_from_forgery with: :exception before_action :authenticate_user! # Enforces auth for all pages—remove if you only need current_user on specific pages end
If you don't want to enforce authentication site-wide, you can manually load current_user like this (though using Devise's built-in method is cleaner):
def set_current_user if session["warden.user.user.key"].present? user_id = session["warden.user.user.key"][0][0] @current_user = User.find(user_id) end end
- Log into your Rails 4 app first—this sets the session cookie in your browser.
- Navigate to your Rails 5 app, and in a controller or view, add
<%= current_user.inspect %>to verify the user loads correctly. - If it's not working, check these common issues:
- Is the session cookie showing up in your browser's dev tools with the correct key (
_app_store) and domain? - Did you copy the exact
secret_key_basefrom Rails 4 to Rails 5? - Are both apps running on the same domain (including subdomains)?
- Is the session cookie showing up in your browser's dev tools with the correct key (
If your apps use HTTPS, update the session store config to include secure and SameSite settings to comply with modern browser standards:
Rails.application.config.session_store :cookie_store, key: '_app_store', domain: '.yourdomain.com', secure: true, same_site: :lax
内容的提问来源于stack exchange,提问作者Adam Young

