Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ## user.rb
- require 'digest/sha1'
- class User < ActiveRecord::Base
- has_many :location
- has_one :default_location, :foreign_key => :user_id, :class_name => 'Location'
- # Virtual attribute for the unencrypted password
- attr_accessor :password
- validates_presence_of :login, :email
- validates_presence_of :password
- validates_presence_of :password_confirmation
- validates_length_of :password, :within => 4..40, :if => :password_present?
- validates_confirmation_of :password, :if => :password_present?
- validates_length_of :login, :within => 3..40, :if => :login_present?
- validates_length_of :email, :within => 3..100, :if => :email_present?
- validates_uniqueness_of :login, :email, :case_sensitive => false
- validates_each :birthdate do |record, attr, value|
- record.errors.add.attr("You're not old enough.") if value > Date.new((Date.today.year - 21),(Date.today.month),(Date.today.day))
- end
- before_save :encrypt_password
- # prevents a user from submitting a crafted form that bypasses activation
- # anything else you want your user to change should be added here.
- attr_accessible :login, :email, :password, :password_confirmation
- acts_as_state_machine :initial => :pending
- state :passive
- state :pending, :enter => :make_activation_code
- state :active, :enter => :do_activate
- state :suspended
- state :deleted, :enter => :do_delete
- event :register do
- transitions :from => :passive, :to => :pending, :guard => Proc.new {|u| !(u.crypted_password.blank? && u.password.blank?) }
- end
- event :activate do
- transitions :from => :pending, :to => :active
- end
- event :suspend do
- transitions :from => [:passive, :pending, :active], :to => :suspended
- end
- event :delete do
- transitions :from => [:passive, :pending, :active, :suspended], :to => :deleted
- end
- event :unsuspend do
- transitions :from => :suspended, :to => :active, :guard => Proc.new {|u| !u.activated_at.blank? }
- transitions :from => :suspended, :to => :pending, :guard => Proc.new {|u| !u.activation_code.blank? }
- transitions :from => :suspended, :to => :passive
- end
- # Authenticates a user by their login name and unencrypted password. Returns the user or nil.
- def self.authenticate(login, password)
- u = find_in_state :first, :active, :conditions => {:login => login} # need to get the salt
- u && u.authenticated?(password) ? u : nil
- end
- # Encrypts some data with the salt.
- def self.encrypt(password, salt)
- Digest::SHA1.hexdigest("--#{salt}--#{password}--")
- end
- # Encrypts the password with the user salt
- def encrypt(password)
- self.class.encrypt(password, salt)
- end
- def authenticated?(password)
- crypted_password == encrypt(password)
- end
- def remember_token?
- remember_token_expires_at && Time.now.utc < remember_token_expires_at
- end
- # These create and unset the fields required for remembering users between browser closes
- def remember_me
- remember_me_for 2.weeks
- end
- def remember_me_for(time)
- remember_me_until time.from_now.utc
- end
- def remember_me_until(time)
- self.remember_token_expires_at = time
- self.remember_token = encrypt("#{email}--#{remember_token_expires_at}")
- save(false)
- end
- def forget_me
- self.remember_token_expires_at = nil
- self.remember_token = nil
- save(false)
- end
- def forgot_password
- @forgotten_password = true
- self.make_password_reset_code
- end
- def reset_password
- # First update the password_reset_code before setting the
- # reset_password flag to avoid duplicate email notifications.
- update_attribute(:password_reset_code, nil)
- @reset_password = true
- end
- #used in user_observer
- def recently_forgot_password?
- @forgotten_password
- end
- def recently_reset_password?
- @reset_password
- end
- def self.find_for_forget(email)
- find_in_state :first, :active, :conditions => {:email => email}
- end
- # Returns true if the user has just been activated.
- def recently_activated?
- @activated
- end
- protected
- # before filter
- def encrypt_password
- return if password.blank?
- self.salt = Digest::SHA1.hexdigest("--#{Time.now.to_s}--#{login}--") if new_record?
- self.crypted_password = encrypt(password)
- end
- def password_present?
- !password.blank?
- end
- def login_present?
- !login.blank?
- end
- def email_present?
- !email.blank?
- end
- def make_activation_code
- self.deleted_at = nil
- self.activation_code = Digest::SHA1.hexdigest( Time.now.to_s.split(//).sort_by {rand}.join )
- end
- def make_password_reset_code
- self.password_reset_code = Digest::SHA1.hexdigest( Time.now.to_s.split(//).sort_by {rand}.join )
- end
- def make_email_update_code
- self.email_update_code = Digest::SHA1.hexdigest( Time.now.to_s.split(//).sort_by {rand}.join )
- end
- def do_delete
- self.deleted_at = Time.now.utc
- end
- def do_activate
- @activated = true
- self.activated_at = Time.now.utc
- self.deleted_at = self.activation_code = nil
- end
- end
- ## users_controller.rb
- class UsersController < ApplicationController
- # Protect these actions behind an admin login
- # before_filter :admin_required, :only => [:suspend, :unsuspend, :destroy, :purge]
- before_filter :login_required, :only => [:suspend, :unsuspend, :destroy, :purge]
- before_filter :find_user, :only => [:show, :suspend, :unsuspend, :destroy, :purge]
- def index
- @users = User.find(:all)
- end
- # render new.rhtml
- def new
- end
- def create
- cookies.delete :auth_token
- # protects against session fixation attacks, wreaks havoc with
- # request forgery protection.
- # uncomment at your own risk
- # reset_session
- @user = User.new(params[:user])
- @user.register! if @user.valid?
- params[:location][:name] = "Default"
- @location = Location.new(params[:location])
- @user.default_location = @location
- if @user.errors.empty?
- #self.current_user = @user
- #redirect_back_or_default('/')
- if @user.default_location.errors.empty?
- flash[:notice] = "Thanks for signing up! Please check your email to activate your account before logging in."
- redirect_to login_path
- else
- @user.destroy
- #@user.errors.add_to_base("There was a problem creating your account because of your default location.")
- render :action => 'new'
- end
- else
- #@user.errors.add_to_base("There was a problem creating your account.")
- render :action => 'new'
- end
- end
- def activate
- self.current_user = params[:activation_code].blank? ? false : User.find_by_activation_code(params[:activation_code])
- if logged_in? && !current_user.active?
- current_user.activate!
- flash[:notice] = "Signup complete!"
- end
- redirect_back_or_default('/')
- end
- def show
- end
- def suspend
- @user.suspend!
- redirect_to users_path
- end
- def unsuspend
- @user.unsuspend!
- redirect_to users_path
- end
- def destroy
- @user.delete!
- redirect_to users_path
- end
- def purge
- @user.destroy
- redirect_to users_path
- end
- protected
- def find_user
- @user = User.find(params[:id])
- end
- end
- ## new.html.erb
- <%= error_messages_for @user, @location %>
- <% form_for :user, :url => users_path do |f| -%>
- <% fields_for :user do |u| %>
- <p><label for="login">Login</label><br/>
- <%= u.text_field :login %></p>
- <p><label for="email">Email</label><br/>
- <%= u.text_field :email %></p>
- <p><label for="password">Password</label><br/>
- <%= u.password_field :password %></p>
- <p><label for="password_confirmation">Confirm Password</label><br/>
- <%= u.password_field :password_confirmation %></p>
- <p><label for="birthdate">Birthdate</label><br/>
- <%= date_select( :user, :birthdate, :start_year => 1900 )%></p>
- <% end %>
- <% fields_for :location do |l| %>
- <p><label for="zipcode">Zipcode</label><br/>
- <%= l.text_field :zipcode %></p>
- <% end %>
- <p><%= submit_tag 'Sign up' %></p>
- <% end -%>
Add Comment
Please, Sign In to add comment