Rails Devise 特定页面出现 401 未授权错误

6
我遇到了一个问题,无法确定我的应用程序为什么返回401未经授权。在未登录的情况下,我的Institutions控制器中的其他操作都可以正常工作。但是,这个页面和另一个页面返回401。如果已登录,则这些页面可以完美地工作,但不应要求登录。我甚至已经清空了视图和操作,但页面仍然返回401。在通过fiddler进行调试时,我只收到一个302重定向。
我尝试在其他地方进行研究,并尝试了Warden authentication recalls 401 Unauthorized的解决方案,但没有成功。 控制台
Started GET "/institutions/3" for 127.0.0.1 at 2013-04-25 14:38:15 -0400
    Processing by InstitutionsController#show as HTML
      Parameters: {"id"=>"3"}
      ←[1m←[36mInstitution Load (0.0ms)←[0m  ←[1mSELECT `institutions`.* FROM `institutions` WHERE `institutions`.`id` = 3 LIMIT 1←[0m

Load data...
Load assets...

然后我提交表单,方法设置为GET。
Started GET "/visit/schedule/preview?utf8=%E2%9C%93&selected_ids=4693" for 127.0.0.1 at 2013
-04-25 14:28:53 -0400
Processing by InstitutionsController#previewselectedvisits as HTML
  Parameters: {"utf8"=>"", "selected_ids"=>"4693"}
Completed 401 Unauthorized in 0ms

Started GET "/users/sign_in" for 127.0.0.1 at 2013-04-25 14:28:53 -0400
Processing by Devise::SessionsController#new as HTML
  Rendered devise/sessions/new.html.erb within layouts/application (15.6ms)
  Rendered auth/_login.html.erb (0.0ms)
  Rendered auth/_loginmodal.html.erb (0.0ms)
  Rendered shared/_navbarout.html.erb (0.0ms)
  Rendered shared/_navbar.html.erb (0.0ms)
  ←[1m←[36mInstitution Load (0.0ms)←[0m  ←[1mSELECT name FROM `institutions` ←[0m
  Rendered search/_searchbar.html.erb (0.0ms)
  Rendered search/_searchresults.html.erb (0.0ms)
  Rendered shared/_footer.html.erb (0.0ms)
Completed 200 OK in 140ms (Views: 46.8ms | ActiveRecord: 15.6ms)

Load assets...

相关路由
devise_for :users
match 'visit/schedule/preview' => 'institutions#previewselectedvisits', :as => :preview_visits, :via => :get
match "institutions/:id" => "institutions#show", :as => :show_institution

rake routes

    new_user_session GET    /users/sign_in(.:format)                             devise/sessions#new
              user_session POST   /users/sign_in(.:format)                             devise/sessions#create
      destroy_user_session DELETE /users/sign_out(.:format)                            devise/sessions#destroy
             user_password POST   /users/password(.:format)                            devise/passwords#create
         new_user_password GET    /users/password/new(.:format)                        devise/passwords#new
        edit_user_password GET    /users/password/edit(.:format)                       devise/passwords#edit
                           PUT    /users/password(.:format)                            devise/passwords#update
  cancel_user_registration GET    /users/cancel(.:format)                              devise_invitable/registrations#cancel
         user_registration POST   /users(.:format)                                     devise_invitable/registrations#create
     new_user_registration GET    /users/sign_up(.:format)                             devise_invitable/registrations#new
    edit_user_registration GET    /users/edit(.:format)                                devise_invitable/registrations#edit
                           PUT    /users(.:format)                                     devise_invitable/registrations#update
                           DELETE /users(.:format)                                     devise_invitable/registrations#destroy
         user_confirmation POST   /users/confirmation(.:format)                        devise/confirmations#create
     new_user_confirmation GET    /users/confirmation/new(.:format)                    devise/confirmations#new
                           GET    /users/confirmation(.:format)                        devise/confirmations#show
               user_unlock POST   /users/unlock(.:format)                              devise/unlocks#create
           new_user_unlock GET    /users/unlock/new(.:format)                          devise/unlocks#new
                           GET    /users/unlock(.:format)                              devise/unlocks#show
    accept_user_invitation GET    /users/invitation/accept(.:format)                   devise/invitations#edit
    remove_user_invitation GET    /users/invitation/remove(.:format)                   devise/invitations#destroy
           user_invitation POST   /users/invitation(.:format)                          devise/invitations#create
       new_user_invitation GET    /users/invitation/new(.:format)                      devise/invitations#new
                           PUT    /users/invitation(.:format)                          devise/invitations#update
            preview_visits GET    /visit/schedule/preview(.:format)                    institutions#previewselectedvisits
          show_institution        /institutions/:id(.:format)                          institutions#show
          vote_institution        /institutions/:id/vote/:visittype_id(.:format)       institutions#vote
                                  /institutions/:id/:offset(.:format)                  institutions#show
              institutions        /institutions(.:format)                              institutions#index
           schedule_visits        /schedule(.:format)                                  institutions#index
              auth_failure        /auth/failure(.:format)                              services#failure
                                  /auth/:service/:callback(.:format)                   services#create
                  services GET    /services(.:format)                                  services#index
                           POST   /services(.:format)                                  services#create
                   service DELETE /services/:id(.:format)                              services#destroy
                login_user        /users/login(.:format)                               users#login
             myvisits_user        /users/myvisits(.:format)                            users#myvisits
       email_myvisits_user        /users/myvisits/email(.:format)                      users#emailmyvisits
    remove_visit_from_user        /users/removevisit/:id/:user_id(.:format)            users#rmvisit
            addvisits_user        /users/addvisits(.:format)                           users#addvisits
          changevisit_user        /users/visits/:user_id/:visit_id/:is_going(.:format) users#toggle_user_going_on_visit
        add_family_to_user        /users/invite(.:format)                              users#addfamilymember
add_family_default_to_user        /users/profile/addfamilymemberdefault(.:format)      users#addfamilymember_default
   remove_family_from_user        /users/profile/removefamilymember(.:format)          users#rmfamilymember
       update_profile_user        /users/profile/update(.:format)                      users#update
 update_profile_other_user        /users/profile/update/:id(.:format)                  users#update
         edit_profile_user        /users/profile/edit(.:format)                        users#edit
         show_profile_user        /users/profile(.:format)                             users#show
                     users        /users(.:format)                                     users#show
                  families GET    /families(.:format)                                  families#index
                           POST   /families(.:format)                                  families#create
                new_family GET    /families/new(.:format)                              families#new
               edit_family GET    /families/:id/edit(.:format)                         families#edit
                    family GET    /families/:id(.:format)                              families#show
                           PUT    /families/:id(.:format)                              families#update
                           DELETE /families/:id(.:format)                              families#destroy
                    visits        /visits(.:format)                                    visits#index
                   company        /company(.:format)                                   company#aboutus
                       edu        /edu(.:format)                                       edu#index
                      root        /                                                    institutions#index

Gemfile

source 'https://rubygems.org'
gem 'rails', '3.2.12'
gem 'mysql2'
gem 'execjs'
group :assets do
  gem 'sass-rails',   '~> 3.2.3'
  gem 'coffee-rails', '~> 3.2.1'
  gem 'uglifier', '>= 1.0.3'
end

gem 'jquery-rails'
gem 'simple_form'

gem 'devise'
gem 'devise_invitable'
gem 'omniauth'
gem "omniauth-google-oauth2"
gem 'omniauth-linkedin-oauth2'
gem 'omniauth-facebook'

#in-place editing
gem 'best_in_place'

#email template convert to inline
gem 'roadie'

#amazon web services and images
gem 'paperclip'
gem 'aws-sdk'

你能列出你的Gemfile中有哪些gem吗?通常情况下,授权是通过一个独立于身份验证的单独的gem来完成的。 - Tilo
谢谢@Tilo,Gemfile已添加。 - Michael
似乎授权在您的应用程序中是手动实现的。 - Tilo
我一直在InstitutionsController中使用current_user,但始终只包含在一个操作中。其中一个操作是institutions#show,它可以正常工作,而不管用户是否已登录,但仍然使用了current_user。previewselectedvisits操作目前为空,视图也是如此,但仍然返回401。ApplicationController没有使用current_user。 - Michael
实际上,我是因为你才找到它的。 - Michael
显示剩余2条评论
1个回答

13

检查您的InstitutionsController和ApplicationController的代码--查找其中带有current_userbefore_filter语句的部分。

 class InstitutionsController < ApplicationController
    before_filter :login_required, :only => [:method1,:method2]
    ...
 end

可能是因为你试图调用的方法需要身份验证,但你没有登录。

你能否在InstitutionsController中发布包含preview方法的摘录?

另一个可能的问题是你的路由定义可能不正确:

  match 'visit/schedule/preview' => 'institutions#previewselectedvisits', :as => :preview_visits, :via => :get

机构控制器(InstitutionsController)真的有一个名为 previewselectedvisits 的方法吗?


非常感谢,你比我更快地回答了这个问题...你让我朝着正确的方向前进(在我看到这个之前,这是完全正确的)。非常感谢。我有这段代码 before_filter :authenticate_user!,:except => [:index, :show]。 - Michael
它不允许我再23个小时内颁发赏金,但我会回来确保我会这样做。再次感谢。 - Michael
远程调试 :) 很高兴它有帮助 - Tilo
我一直在苦思冥想,甚至因为太兴奋不小心踢翻了整杯茶。你真是太棒了。 - Michael
@Michael,我是Rails的新手,我也遇到了你遇到的类似问题,但我无法理解我的问题,也不知道如何解决它,所以能否请你帮忙解决这个问题?http://stackoverflow.com/questions/21270126/rails-unable-get-the-devise-login-pop-when-clicking-view - user3144005

网页内容由stack overflow 提供, 点击上面的
可以查看英文原文,
原文链接