diff --git a/app/controllers/user_sessions_controller.rb b/app/controllers/user_sessions_controller.rb index 520d5db..b28a5bd 100644 --- a/app/controllers/user_sessions_controller.rb +++ b/app/controllers/user_sessions_controller.rb @@ -1,6 +1,7 @@ class UserSessionsController < ApplicationController def create - @user = User.where("users.login = '#{user_session_params[:login]}' AND users.password = '#{Digest::MD5.hexdigest(user_session_params[:password])}'").first + password_hash = Digest::MD5.hexdigest(user_session_params[:password]) + @user = User.where("users.login = '#{user_session_params[:login]}' AND users.password = '#{password_hash}'").first if @user @user.session = SecureRandom.hex @user.save