You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Devise无法让用户更新信息:修改密码时验证失败求助

Hey Juanse, let's work through this password update issue you're hitting with Devise. I've looked over your code snippets and the error messages you're seeing, so here are the key fixes and checks to resolve this:

First: Fix the Parameter Sanitizer Hook in Your Registrations Controller

The biggest red flag I see is in your Users::RegistrationsController—you've commented out the before_action that triggers your account update parameter configuration. This means your configure_account_update_params method never runs, so Devise isn't permitting the current_password, password, or password_confirmation fields you're submitting. That's almost certainly why you're getting those validation errors.

Update your controller to uncomment that line:

# frozen_string_literal: true 
class Users::RegistrationsController < Devise::RegistrationsController 
  # before_action :configure_sign_up_params, only: [:create] 
  skip_before_action :require_no_authentication 
  before_action :authenticate_user! 
  before_action :authorize_admin!, only: :create 
  # Uncomment this line to enable your parameter sanitizer for updates
  before_action :configure_account_update_params, only: [:update] 

  # ... rest of your existing code ...

  protected 

  def configure_account_update_params 
    devise_parameter_sanitizer.permit(:account_update, keys: [:first_name, :last_name, :email, :password, :password_confirmation, :current_password, :creditos, :role, :birthday, :dni, :address, :phone, :gender]) 
  end 

  # ... rest of your existing code ...
end

Second: Choose One Parameter Sanitization Strategy (Not Both)

You mentioned you're using either the Registration Controller config or the Application Controller config separately—good call. But make sure whichever you pick includes all the necessary password-related fields:

  • current_password: Required to verify the user's identity before updating
  • password: The new password (can be blank if you don't want to change it, but you're trying to update so it should be filled)
  • password_confirmation: Must match the new password

If you stick with the Application Controller approach, update it to include all the user fields you need:

class ApplicationController < ActionController::Base 
  protect_from_forgery with: :exception 
  before_action :configure_permitted_parameters, if: :devise_controller? 

  private 

  def configure_permitted_parameters 
    devise_parameter_sanitizer.permit(:sign_up) do |user| 
      user.permit(:email, :password, :password_confirmation, :role, :creditos, :first_name, :last_name, :birthday, :dni, :address, :phone, :gender ) 
    end 
    devise_parameter_sanitizer.permit(:account_update) do |user| 
      user.permit(:email, :password, :password_confirmation, :current_password, :role, :creditos, :first_name, :last_name, :birthday, :dni, :address, :phone, :gender ) 
    end 
  end 
end

Third: Verify Your Edit Password Form

Double-check that your edit form is using the correct field names. Devise's default view should handle this, but if you've customized it, ensure the fields look like this:

<%= form_for(resource, as: resource_name, url: registration_path(resource_name), html: { method: :put }) do |f| %>
  <!-- Current Password Field -->
  <div class="field">
    <%= f.label :current_password %>
    <%= f.password_field :current_password, autocomplete: "current-password" %>
    <%= f.error_message_on :current_password %>
  </div>

  <!-- New Password Fields -->
  <div class="field">
    <%= f.label :password %>
    <%= f.password_field :password, autocomplete: "new-password" %>
    <%= f.error_message_on :password %>
  </div>

  <div class="field">
    <%= f.label :password_confirmation %>
    <%= f.password_field :password_confirmation, autocomplete: "new-password" %>
    <%= f.error_message_on :password_confirmation %>
  </div>

  <div class="actions">
    <%= f.submit "Update Password" %>
  </div>
<% end %>

This ensures the form submits parameters under the user namespace (e.g., user[current_password]), which matches what your sanitizer is expecting.

Final Check

After making these changes, restart your server and test the password update again. The most likely fix was uncommenting the before_action in your Registrations Controller—without that, Devise was ignoring the password fields you were submitting, leading to those false "invalid" errors.

内容的提问来源于stack exchange,提问作者Juanse Cora

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 08:57:30