1
0
Fork 0
mirror of https://github.com/maybe-finance/maybe.git synced 2025-07-26 00:29:40 +02:00
Maybe/app/controllers/sessions_controller.rb

45 lines
1.6 KiB
Ruby
Raw Normal View History

2024-02-02 09:05:04 -06:00
class SessionsController < ApplicationController
before_action :set_session, only: :destroy
2024-04-03 10:35:55 -04:00
skip_authentication only: %i[new create]
2024-02-02 09:05:04 -06:00
layout "auth"
2024-02-02 09:05:04 -06:00
def new
Rails.logger.info "SessionsController#new - Rendering login form"
2024-02-02 09:05:04 -06:00
end
def create
Rails.logger.info "SessionsController#create - Attempting to authenticate user with email: #{params[:email]}"
2024-02-02 09:05:04 -06:00
if user = User.authenticate_by(email: params[:email], password: params[:password])
Rails.logger.info "SessionsController#create - Authentication successful for user: #{user.id}"
if user.otp_required?
Rails.logger.info "SessionsController#create - MFA required for user: #{user.id}, redirecting to MFA verification"
session[:mfa_user_id] = user.id
redirect_to verify_mfa_path
else
Rails.logger.info "SessionsController#create - MFA not required for user: #{user.id}, creating session"
@session = create_session_for(user)
Rails.logger.info "SessionsController#create - Session created: #{@session.id}, redirecting to root_path"
redirect_to root_path
end
2024-02-02 09:05:04 -06:00
else
Rails.logger.info "SessionsController#create - Authentication failed for email: #{params[:email]}"
flash.now[:alert] = t(".invalid_credentials")
2024-02-02 09:05:04 -06:00
render :new, status: :unprocessable_entity
end
end
2024-02-02 09:05:04 -06:00
def destroy
Rails.logger.info "SessionsController#destroy - Destroying session: #{@session.id} for user: #{Current.user.id}"
@session.destroy
redirect_to new_session_path, notice: t(".logout_successful")
2024-02-02 09:05:04 -06:00
end
private
def set_session
@session = Current.user.sessions.find(params[:id])
end
2024-02-02 09:05:04 -06:00
end