Devise无法让用户更新信息:修改密码时验证失败求助
Hey Juanse, let's work through this password update issue you're hitting with Devise. I've looked over your code snippets and the error messages you're seeing, so here are the key fixes and checks to resolve this:
First: Fix the Parameter Sanitizer Hook in Your Registrations Controller
The biggest red flag I see is in your Users::RegistrationsController—you've commented out the before_action that triggers your account update parameter configuration. This means your configure_account_update_params method never runs, so Devise isn't permitting the current_password, password, or password_confirmation fields you're submitting. That's almost certainly why you're getting those validation errors.
Update your controller to uncomment that line:
# frozen_string_literal: true class Users::RegistrationsController < Devise::RegistrationsController # before_action :configure_sign_up_params, only: [:create] skip_before_action :require_no_authentication before_action :authenticate_user! before_action :authorize_admin!, only: :create # Uncomment this line to enable your parameter sanitizer for updates before_action :configure_account_update_params, only: [:update] # ... rest of your existing code ... protected def configure_account_update_params devise_parameter_sanitizer.permit(:account_update, keys: [:first_name, :last_name, :email, :password, :password_confirmation, :current_password, :creditos, :role, :birthday, :dni, :address, :phone, :gender]) end # ... rest of your existing code ... end
Second: Choose One Parameter Sanitization Strategy (Not Both)
You mentioned you're using either the Registration Controller config or the Application Controller config separately—good call. But make sure whichever you pick includes all the necessary password-related fields:
current_password: Required to verify the user's identity before updatingpassword: The new password (can be blank if you don't want to change it, but you're trying to update so it should be filled)password_confirmation: Must match the new password
If you stick with the Application Controller approach, update it to include all the user fields you need:
class ApplicationController < ActionController::Base protect_from_forgery with: :exception before_action :configure_permitted_parameters, if: :devise_controller? private def configure_permitted_parameters devise_parameter_sanitizer.permit(:sign_up) do |user| user.permit(:email, :password, :password_confirmation, :role, :creditos, :first_name, :last_name, :birthday, :dni, :address, :phone, :gender ) end devise_parameter_sanitizer.permit(:account_update) do |user| user.permit(:email, :password, :password_confirmation, :current_password, :role, :creditos, :first_name, :last_name, :birthday, :dni, :address, :phone, :gender ) end end end
Third: Verify Your Edit Password Form
Double-check that your edit form is using the correct field names. Devise's default view should handle this, but if you've customized it, ensure the fields look like this:
<%= form_for(resource, as: resource_name, url: registration_path(resource_name), html: { method: :put }) do |f| %> <!-- Current Password Field --> <div class="field"> <%= f.label :current_password %> <%= f.password_field :current_password, autocomplete: "current-password" %> <%= f.error_message_on :current_password %> </div> <!-- New Password Fields --> <div class="field"> <%= f.label :password %> <%= f.password_field :password, autocomplete: "new-password" %> <%= f.error_message_on :password %> </div> <div class="field"> <%= f.label :password_confirmation %> <%= f.password_field :password_confirmation, autocomplete: "new-password" %> <%= f.error_message_on :password_confirmation %> </div> <div class="actions"> <%= f.submit "Update Password" %> </div> <% end %>
This ensures the form submits parameters under the user namespace (e.g., user[current_password]), which matches what your sanitizer is expecting.
Final Check
After making these changes, restart your server and test the password update again. The most likely fix was uncommenting the before_action in your Registrations Controller—without that, Devise was ignoring the password fields you were submitting, leading to those false "invalid" errors.
内容的提问来源于stack exchange,提问作者Juanse Cora

