user deletions: fix error when given incorrect password.
Use validations instead of raising an exception when the password is incorrect so that the controller can display errors sensibly. Also fix users being logged out even when the deletion attempt failed due to an incorrect password.
This commit is contained in:
@@ -1,14 +1,23 @@
|
||||
module Maintenance
|
||||
module User
|
||||
class DeletionsController < ApplicationController
|
||||
respond_to :html, :json, :xml
|
||||
|
||||
def show
|
||||
end
|
||||
|
||||
def destroy
|
||||
deletion = UserDeletion.new(CurrentUser.user, params.dig(:user, :password))
|
||||
deletion.delete!
|
||||
session.delete(:user_id)
|
||||
redirect_to(posts_path, :notice => "You are now logged out")
|
||||
|
||||
if deletion.errors.none?
|
||||
session.delete(:user_id)
|
||||
flash[:notice] = "Your account has been deactivated"
|
||||
respond_with(deletion, location: posts_path)
|
||||
else
|
||||
flash[:notice] = deletion.errors.full_messages.join("; ")
|
||||
redirect_to maintenance_user_deletion_path
|
||||
end
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user