Recoverable takes care of reseting the user password and send reset instructions.
Recoverable adds the following options to devise_for:
* +reset_password_keys+: the keys you want to use when recovering the password for an account
# resets the user password and save the record, true if valid passwords are given, otherwise false User.find(1).reset_password!('password123', 'password123') # only resets the user password, without saving the record user = User.find(1) user.reset_password('password123', 'password123') # creates a new token and send it with instructions about how to reset the password User.find(1).send_reset_password_instructions
Update password saving the record and clearing token. Returns true if the passwords are valid and the record was saved, false otherwise.
# File lib/devise/models/recoverable.rb, line 29 def reset_password!(new_password, new_password_confirmation) self.password = new_password self.password_confirmation = new_password_confirmation if valid? clear_reset_password_token after_password_reset end save end
Checks if the reset password token sent is within the limit time. We do this by calculating if the difference between today and the sending date does not exceed the confirm in time configured. Returns true if the resource is not responding to reset_password_sent_at at all. reset_password_within is a model configuration, must always be an integer value.
Example:
# reset_password_within = 1.day and reset_password_sent_at = today reset_password_period_valid? # returns true # reset_password_within = 5.days and reset_password_sent_at = 4.days.ago reset_password_period_valid? # returns true # reset_password_within = 5.days and reset_password_sent_at = 5.days.ago reset_password_period_valid? # returns false # reset_password_within = 0.days reset_password_period_valid? # will always return false
# File lib/devise/models/recoverable.rb, line 67 def reset_password_period_valid? reset_password_sent_at && reset_password_sent_at.utc >= self.class.reset_password_within.ago end
Resets reset password token and send reset password instructions by email
# File lib/devise/models/recoverable.rb, line 42 def send_reset_password_instructions generate_reset_password_token! if should_generate_reset_token? self.devise_mailer.reset_password_instructions(self).deliver end
# File lib/devise/models/recoverable.rb, line 96 def after_password_reset end
Removes reset_password token
# File lib/devise/models/recoverable.rb, line 91 def clear_reset_password_token self.reset_password_token = nil self.reset_password_sent_at = nil end
Generates a new random token for reset password
# File lib/devise/models/recoverable.rb, line 78 def generate_reset_password_token self.reset_password_token = self.class.reset_password_token self.reset_password_sent_at = Time.now.utc self.reset_password_token end
Resets the reset password token with and save the record without validating
# File lib/devise/models/recoverable.rb, line 86 def generate_reset_password_token! generate_reset_password_token && save(:validate => false) end
# File lib/devise/models/recoverable.rb, line 73 def should_generate_reset_token? reset_password_token.nil? || !reset_password_period_valid? end