Guest User

Untitled

a guest
Apr 7th, 2018
86
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.94 KB | None | 0 0
  1. require 'digest/sha1'
  2.  
  3. class User < ActiveRecord::Base
  4. # Virtual attribute for the unencrypted password
  5. attr_accessor :password
  6.  
  7. validates_presence_of :login, :email, :first_name, :last_name
  8. validates_presence_of :password, :if => :password_required?
  9. validates_presence_of :password_confirmation, :if => :password_required?
  10. validates_length_of :password, :within => 4..40, :if => :password_required?
  11. validates_confirmation_of :password, :if => :password_required?
  12. validates_length_of :login, :within => 3..40
  13. validates_length_of :first_name, :within => 3..40
  14. validates_length_of :last_name, :within => 3..40
  15. validates_length_of :email, :within => 3..100
  16. validates_uniqueness_of :login, :email, :case_sensitive => false
  17. before_save :encrypt_password
  18.  
  19. # prevents a user from submitting a crafted form that bypasses activation
  20. # anything else you want your user to change should be added here.
  21. attr_accessible :login, :email, :password, :password_confirmation, :first_name, :last_name
  22.  
  23. acts_as_state_machine :initial => :pending
  24. state :passive
  25. state :pending, :enter => :make_activation_code
  26. state :active, :enter => :do_activate
  27. state :suspended
  28. state :deleted, :enter => :do_delete
  29.  
  30. event :register do
  31. transitions :from => :passive, :to => :pending, :guard => Proc.new {|u| !(u.crypted_password.blank? && u.password.blank?) }
  32. end
  33.  
  34. event :activate do
  35. transitions :from => :pending, :to => :active
  36. end
  37.  
  38. event :suspend do
  39. transitions :from => [:passive, :pending, :active], :to => :suspended
  40. end
  41.  
  42. event :delete do
  43. transitions :from => [:passive, :pending, :active, :suspended], :to => :deleted
  44. end
  45.  
  46. event :unsuspend do
  47. transitions :from => :suspended, :to => :active, :guard => Proc.new {|u| !u.activated_at.blank? }
  48. transitions :from => :suspended, :to => :pending, :guard => Proc.new {|u| !u.activation_code.blank? }
  49. transitions :from => :suspended, :to => :passive
  50. end
  51.  
  52. def self.force_activate_now(id)
  53. user = self.find(id)
  54. user.activation_code = nil
  55. user.activated_at = Time.now.utc
  56. user.state = 'active'
  57. user.save!
  58. end
  59.  
  60. # Authenticates a user by their login name and unencrypted password. Returns the user or nil.
  61. def self.authenticate(login, password)
  62. u = find_in_state :first, :active, :conditions => {:login => login} # need to get the salt
  63. u && u.authenticated?(password) ? u : nil
  64. end
  65.  
  66. # Encrypts some data with the salt.
  67. def self.encrypt(password, salt)
  68. Digest::SHA1.hexdigest("--#{salt}--#{password}--")
  69. end
  70.  
  71. # Encrypts the password with the user salt
  72. def encrypt(password)
  73. self.class.encrypt(password, salt)
  74. end
  75.  
  76. def authenticated?(password)
  77. crypted_password == encrypt(password)
  78. end
  79.  
  80. def remember_token?
  81. remember_token_expires_at && Time.now.utc < remember_token_expires_at
  82. end
  83.  
  84. # These create and unset the fields required for remembering users between browser closes
  85. def remember_me
  86. remember_me_for 2.weeks
  87. end
  88.  
  89. def remember_me_for(time)
  90. remember_me_until time.from_now.utc
  91. end
  92.  
  93. def remember_me_until(time)
  94. self.remember_token_expires_at = time
  95. self.remember_token = encrypt("#{email}--#{remember_token_expires_at}")
  96. save(false)
  97. end
  98.  
  99. def forget_me
  100. self.remember_token_expires_at = nil
  101. self.remember_token = nil
  102. save(false)
  103. end
  104.  
  105. def forgot_password
  106. @forgotten_password = true
  107. self.make_password_reset_code
  108. end
  109.  
  110. def reset_password
  111. # First update the password_reset_code before setting the
  112. # reset_password flag to avoid duplicate email notifications.
  113. update_attributes(:password_reset_code => nil)
  114. @reset_password = true
  115. end
  116.  
  117. #used in user_observer
  118. def recently_forgot_password?
  119. @forgotten_password
  120. end
  121.  
  122. def recently_reset_password?
  123. @reset_password
  124. end
  125.  
  126. def recently_activated?
  127. @recent_active
  128. end
  129.  
  130. protected
  131. # before filter
  132. def encrypt_password
  133. return if password.blank?
  134. self.salt = Digest::SHA1.hexdigest("--#{Time.now.to_s}--#{login}--") if new_record?
  135. self.crypted_password = encrypt(password)
  136. end
  137.  
  138. def password_required?
  139. crypted_password.blank? || !password.blank?
  140. end
  141.  
  142. def make_activation_code
  143. self.deleted_at = nil
  144. self.activation_code = Digest::SHA1.hexdigest( Time.now.to_s.split(//).sort_by {rand}.join )
  145. end
  146.  
  147. def do_delete
  148. self.deleted_at = Time.now.utc
  149. end
  150.  
  151. def do_activate
  152. self.activated_at = Time.now.utc
  153. self.deleted_at = self.activation_code = nil
  154. @recent_active = true
  155. end
  156.  
  157. def make_password_reset_code
  158. self.password_reset_code = Digest::SHA1.hexdigest( Time.now.to_s.split(//).sort_by {rand}.join )
  159. end
  160.  
  161. # protected super user create method
  162. def self.suadminmake(id)
  163. user = self.find(id)
  164. user.activation_code = nil
  165. user.activated_at = Time.now.utc
  166. user.state = 'active'
  167. user.admin = true
  168. user.super = true
  169. user.save!
  170. end
  171.  
  172. end
Add Comment
Please, Sign In to add comment