You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Postman向Rails5+Devise发送POST请求创建用户失败求助

问题:Postman请求Rails API创建用户失败,提示email和password为空

我尝试用Postman、Rails 5和Devise Gem创建用户账号,已经给Devise的User模型加了username字段并确认可用,但发送POST请求到http://0.0.0.0:3000/users/时没法正常创建用户。

发送的JSON参数:

{ "username": "username", "email": "name@example.com", "password": "password", "password_confirmation": "password" }

收到的响应:

{ "status": "ERROR", "message": "Could not create new user account", "data": { "email": [ "can't be blank" ], "password": [ "can't be blank" ] } }

自定义的Api::V1::RegistrationsController代码:

module Api
module V1
class RegistrationsController < Devise::RegistrationsController

before_action :configure_permitted_parameters
respond_to :json
def new
  user = User.new(user_params)
end

def create
  user = User.create(username: params[:username],
  email: params[:email],
  password: params[:password],
  password_confirmation: params[:password_confirmation])

  if user.save
    render json: {status: "SUCCESS", message: "Created new user account", data: user }, status: :ok
  else
    render json: {status: "ERROR",
    message: "Could not create new user account",
    data: user.errors},
    status: :unprocessable_entity

  end
end

private

def user_params
  params.require(:user).permit(:username, :email, :password, :password_confirmation)
end

protected

def configure_permitted_parameters
  devise_parameter_sanitizer.permit(:sign_up, keys: [:username])
end

end
end
end

我直接从params哈希里取email和password传入create方法,但响应说这两个字段为空,请问问题原因和解决办法?


问题分析

嘿,这个问题其实是参数结构不匹配+没有正确使用参数过滤方法导致的:

  1. 你定义的user_params要求参数必须嵌套在:user键下(params.require(:user)),但你在Postman里发送的是平级的JSON参数,没有包裹在user对象中;
  2. 你在create方法里直接从顶级params取字段,但如果Rails没有正确解析参数(比如请求头没设置对),或者参数结构不对,就会导致params[:email]、params[:password]都是nil,自然触发验证错误。

解决办法

方案1:使用嵌套参数(推荐,符合Rails最佳实践)

步骤1:修改Postman的请求参数

把发送的JSON改成嵌套结构,所有用户字段放在user键下:

{
  "user": {
    "username": "username",
    "email": "name@example.com",
    "password": "password",
    "password_confirmation": "password"
  }
}

步骤2:修改create方法,使用user_params

把直接构造参数的代码改成用你已经定义好的user_params,这样既安全又符合规范:

def create
  user = User.new(user_params)
  if user.save
    render json: {status: "SUCCESS", message: "Created new user account", data: user }, status: :ok
  else
    render json: {status: "ERROR",
    message: "Could not create new user account",
    data: user.errors},
    status: :unprocessable_entity
  end
end

方案2:保持平级参数(如果不想用嵌套)

步骤1:修改user_params方法

去掉对:user的强制要求,直接允许平级字段:

def user_params
  params.permit(:username, :email, :password, :password_confirmation)
end

步骤2:确认Postman请求头设置

一定要在Postman的请求头里添加Content-Type: application/json,这样Rails才能正确解析你发送的JSON参数,确保params[:email]等字段能拿到对应的值。

步骤3:修改create方法用user_params

同样把构造用户的代码改成用user_params,和方案1的步骤2一样。

额外检查点

  • 确认你的Rails应用允许JSON参数解析:API模式默认开启,普通Web模式请确保config/application.rb里有config.middleware.use ActionDispatch::JsonParser;
  • 检查Postman的请求方式是POST,URL正确(http://0.0.0.0:3000/users/带不带斜杠都可以);
  • 你的configure_permitted_parameters方法没问题,已经把username加入了注册允许参数,不用修改。

内容的提问来源于stack exchange,提问作者Angel Garcia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:37:33