Fix account delete form not accepting password, update suspended (#3745)

account before removing content for quicker feedback to end-users
signup-info-prompt
Eugen Rochko 2017-06-14 20:30:12 +02:00 committed by GitHub
parent 98eacb2238
commit 91c71471ab
3 changed files with 4 additions and 4 deletions

View File

@ -22,6 +22,6 @@ class Settings::DeletesController < ApplicationController
private
def delete_params
params.permit(:password)
params.require(:form_delete_confirmation).permit(:password)
end
end

View File

@ -5,8 +5,8 @@ class SuspendAccountService < BaseService
@account = account
purge_user if remove_user
purge_content
purge_profile
purge_content
unsubscribe_push_subscribers
end

View File

@ -35,7 +35,7 @@ describe Settings::DeletesController do
context 'with correct password' do
before do
delete :destroy, params: { password: 'petsmoldoggos' }
delete :destroy, params: { form_delete_confirmation: { password: 'petsmoldoggos' } }
end
it 'redirects to sign in page' do
@ -53,7 +53,7 @@ describe Settings::DeletesController do
context 'with incorrect password' do
before do
delete :destroy, params: { password: 'blaze420' }
delete :destroy, params: { form_delete_confirmation: { password: 'blaze420' } }
end
it 'redirects back to confirmation page' do