You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Devise Gem添加新管理员问题:需新增两名可查看全量用户的管理员

Adding Additional Admins with Devise & User View Permissions

Hey there! Let's get those two extra admins set up for your Rails app—since you're already using Devise, this should be straightforward. Here's how to add new admins and ensure they have the right permissions to view all users:

1. Create New Admins via Rails Console

This is the quickest way to add admins on the fly:

  • Open your terminal and run the Rails console:
    rails c
    
  • Use these commands to create your two new admins (replace the email and password with your own secure values):
    # First admin
    admin_one = User.create!(
      email: 'admin1@yourdomain.com',
      password: 'StrongPass123!',
      password_confirmation: 'StrongPass123!',
      admin: true
    )
    
    # Second admin
    admin_two = User.create!(
      email: 'admin2@yourdomain.com',
      password: 'AnotherStrongPass456!',
      password_confirmation: 'AnotherStrongPass456!',
      admin: true
    )
    
    The create! method will throw an error if something goes wrong (like duplicate emails), which helps you catch issues quickly.

2. Use Seed Data for Repeatable Setup

If you want these admins to be created automatically whenever you reset or deploy your database, add them to your seed file:

  • Open db/seeds.rb and add:
    # Create admins (only if they don't already exist)
    [
      { email: 'admin1@yourdomain.com', password: 'StrongPass123!' },
      { email: 'admin2@yourdomain.com', password: 'AnotherStrongPass456!' }
    ].each do |admin_data|
      User.create!(
        email: admin_data[:email],
        password: admin_data[:password],
        password_confirmation: admin_data[:password],
        admin: true
      ) unless User.exists?(email: admin_data[:email])
    end
    
  • Run the seed command to populate the admins:
    rails db:seed
    

3. Ensure Admins Can View All Users

Now make sure only admins have access to the full user list. Update your UsersController to add a permission check:

class UsersController < ApplicationController
  # Restrict the index action (where you show all users) to admins only
  before_action :require_admin, only: [:index]

  def index
    @users = User.all # Fetches all users for admins to view
  end

  private

  def require_admin
    # Redirect non-admins to the home page with an alert
    unless current_user&.admin?
      redirect_to root_path, alert: "You don't have permission to view all users."
    end
  end
end

Adjust the only: [:index] part if you have other actions that should be restricted to admins (like editing or deleting users).

Bonus: Convert Existing Users to Admins

If you want to turn existing regular users into admins instead of creating new ones, run this in the Rails console:

# Find the user by email
user = User.find_by(email: 'existing_user@yourdomain.com')
# Update their admin status
user.update!(admin: true)

内容的提问来源于stack exchange,提问作者Harini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 03:25:26