docbrown/app/controllers/confirmations_controller.rb
Fernando Valverde 1eafd7388e
Fix email confirmation logic when registering via Omniauth (#17878)
* Move .skip_confirmation! call to .find_or_create_user! method

* Add regression tests to avoid email confirmation delivery

* Keep the original place where we had user.skip_confirmation! too

* Update logic to require email confirmation from omniauth

* test confirmation is required with SMTP

* Keep :notice instead of :global_notice

* Forem Account bypass email confirmation reorg

* inline comment reorder + clarification

* Apply suggestions from code review

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>

Co-authored-by: Fernando Valverde <fernando@visualcosita.com>
Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>
2022-06-23 16:26:26 -04:00

29 lines
1,018 B
Ruby

class ConfirmationsController < Devise::ConfirmationsController
# GET /resource/confirmation?confirmation_token=abcdef
def show
self.resource = resource_class.confirm_by_token(params[:confirmation_token])
yield resource if block_given?
if resource.errors.empty?
set_flash_message!(:notice, :confirmed)
sign_in(resource)
if resource.creator?
redirect_to new_admin_creator_setting_path
else
respond_with_navigational(resource) { redirect_to after_confirmation_path_for(resource_name, resource) }
end
else
respond_with_navigational(resource.errors, status: :unprocessable_entity) { render :new }
end
end
def create
self.resource = resource_class.send_confirmation_instructions(resource_params)
resource.errors.clear # Don't leak user information, like paranoid mode.
message = I18n.t("confirmations_controller.email_sent", email: ForemInstance.contact_email)
flash.now[:global_notice] = message
render :new
end
end