8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
|
# File 'app/controllers/user_management/authentication_controller.rb', line 8
def create
@user = User.find_by(username: params[:username])
begin
response = JSON.parse(RestClient.post("#{SETTINGS['sss_url']}/authenticate",{'username' => params[:username],'password' => params[:password]}.to_json, {content_type: :json, accept: :json}))
rescue => e
return authenticate_locally
end
response.symbolize_keys!
if response[:isValid] == true
if @user.blank?
ActiveRecord::Base.transaction do
person = Person.create!(first_name: (response[:first_name] || 'N/A'),surname: (response[:last_name] || 'N/A'), sex: (response[:gender] || 'N'))
user = User.create!(username: params[:username], email: '[email protected]', person_id:person.id, password:params[:password],password_confirmation: params[:password_confirmation])
@user = User.find_by(username: params[:username])
end
else
ActiveRecord::Base.transaction do
Person.find_by(person_id: @user.person_id).update(first_name: (response[:first_name] || 'N/A'),surname: (response[:last_name] || 'N'), sex: (response[:gender] || 'N'))
@user.update!(email: '[email protected]', password:params[:password],password_confirmation: params[:password_confirmation])
end
end
authenticate_locally
elsif response[:isValid] == false
if @user
ActiveRecord::Base.connection.execute("UPDATE user set password='password',password_digest='digest' WHERE user_id = #{@user.id}") unless @user
render json: {error: "Invalid username or password", status: 403}, status: :forbidden
else
authenticate_locally
end
elsif response['error']
authenticate_locally
end
end
|