From 360157e0c833a822f5905d49b629d06e0215cbe1 Mon Sep 17 00:00:00 2001 From: sto Date: Wed, 10 Dec 2025 17:50:07 +0100 Subject: [PATCH] Permit password creation --- app/controllers/users_controller.rb | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/app/controllers/users_controller.rb b/app/controllers/users_controller.rb index 1ba9419..1a41a6d 100644 --- a/app/controllers/users_controller.rb +++ b/app/controllers/users_controller.rb @@ -20,7 +20,7 @@ class UsersController < ApplicationController authorize @user @user.password_change_attempt = false - if @user.update(user_params) + if @user.update(user_general_params) redirect_to contests_path, notice: t("users.edit.notice") else render :edit, status: :unprocessable_entity @@ -102,6 +102,10 @@ class UsersController < ApplicationController end def user_params + params.expect(user: [ :username, :email_address, :lang, :password ]) + end + + def user_general_params params.expect(user: [ :username, :email_address, :lang ]) end