Skip to content

Commit 3b5db8e

Browse files
authored
Merge pull request rails#43378 from Stellenticket/set_empty_secure_password
clear secure password cache if password is set to `nil`
2 parents 6acaebd + 9bd186a commit 3b5db8e

File tree

3 files changed

+25
-0
lines changed

3 files changed

+25
-0
lines changed

activemodel/CHANGELOG.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,21 @@
1+
* Clear secure password cache if password is set to `nil`
2+
3+
Before:
4+
5+
user.password = 'something'
6+
user.password = nil
7+
8+
user.password # => 'something'
9+
10+
Now:
11+
12+
user.password = 'something'
13+
user.password = nil
14+
15+
user.password # => nil
16+
17+
*Markus Doits*
18+
119
## Rails 7.0.0.alpha2 (September 15, 2021) ##
220

321
* No changes.

activemodel/lib/active_model/secure_password.rb

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,7 @@ def initialize(attribute)
9494

9595
define_method("#{attribute}=") do |unencrypted_password|
9696
if unencrypted_password.nil?
97+
instance_variable_set("@#{attribute}", nil)
9798
self.public_send("#{attribute}_digest=", nil)
9899
elsif !unencrypted_password.empty?
99100
instance_variable_set("@#{attribute}", unencrypted_password)

activemodel/test/cases/secure_password_test.rb

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -91,6 +91,12 @@ class SecurePasswordTest < ActiveModel::TestCase
9191
assert_equal ["doesn't match Password"], @user.errors[:password_confirmation]
9292
end
9393

94+
test "resetting password to nil clears the password cache" do
95+
@user.password = "password"
96+
@user.password = nil
97+
assert_nil @user.password
98+
end
99+
94100
test "update an existing user with validation and no change in password" do
95101
assert @existing_user.valid?(:update), "user should be valid"
96102
end

0 commit comments

Comments
 (0)