2025-01-01 15:44:50 +08:00
|
|
|
module SessionsHelper
|
|
|
|
def log_in(user)
|
|
|
|
session[:user_id] = user.id
|
2025-01-02 17:49:06 +08:00
|
|
|
# 防范会话重放攻击
|
|
|
|
session[:session_token] = user.session_token
|
2025-01-01 15:44:50 +08:00
|
|
|
end
|
|
|
|
|
2025-01-02 16:47:26 +08:00
|
|
|
def remember(user)
|
|
|
|
user.remember
|
|
|
|
cookies.permanent.encrypted[:user_id] = user.id
|
|
|
|
cookies.permanent[:remember_token] = user.remember_token
|
|
|
|
end
|
|
|
|
|
2025-01-01 15:44:50 +08:00
|
|
|
def current_user
|
2025-01-02 16:47:26 +08:00
|
|
|
if (user_id = session[:user_id])
|
2025-01-02 17:49:06 +08:00
|
|
|
user = User.find_by(id: user_id)
|
|
|
|
if user && session[:session_token] == user.session_token
|
|
|
|
@current_user = user
|
|
|
|
end
|
2025-01-02 16:47:26 +08:00
|
|
|
elsif (user_id = cookies.encrypted[:user_id])
|
|
|
|
user = User.find_by(id: user_id)
|
2025-01-06 18:38:39 +08:00
|
|
|
if user && user.authenticated?(:remember, cookies[:remember_token])
|
2025-01-02 16:47:26 +08:00
|
|
|
log_in user
|
|
|
|
@current_user = user
|
|
|
|
end
|
2025-01-01 15:44:50 +08:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def logged_in?
|
|
|
|
!current_user.nil?
|
|
|
|
end
|
2025-01-02 11:59:27 +08:00
|
|
|
|
2025-01-02 16:47:26 +08:00
|
|
|
def forget(user)
|
|
|
|
user.forget
|
|
|
|
cookies.delete(:user_id)
|
|
|
|
cookies.delete(:remember_token)
|
|
|
|
end
|
|
|
|
|
2025-01-02 11:59:27 +08:00
|
|
|
def log_out
|
2025-01-02 16:47:26 +08:00
|
|
|
forget(current_user)
|
2025-01-02 11:59:27 +08:00
|
|
|
reset_session
|
|
|
|
@current_user = nil
|
|
|
|
end
|
2025-01-03 13:48:59 +08:00
|
|
|
|
|
|
|
def current_user?(user)
|
|
|
|
user && user == current_user
|
|
|
|
end
|
|
|
|
|
|
|
|
def store_location
|
2025-01-04 10:09:27 +08:00
|
|
|
session[:forwarding_url] = request.original_url if
|
|
|
|
request.get? || request.head?
|
2025-01-03 13:48:59 +08:00
|
|
|
end
|
2025-01-01 15:44:50 +08:00
|
|
|
end
|