# omniauth failure callback
def auth_failure
flash[:error] = t(params[:message], :scope => "users.auth_failure", :default => t("users.auth_failure.unknown_error"))
- redirect_to params[:origin] || login_url
+
+ origin = safe_referer(params[:origin]) if params[:origin]
+
+ redirect_to origin || login_url
end
private
assert_equal "deleted", normal_user.reload.status
assert_equal "deleted", confirmed_user.reload.status
end
+
+ def test_auth_failure_callback
+ get auth_failure_path
+ assert_response :redirect
+ assert_redirected_to login_path
+
+ get auth_failure_path, :params => { :origin => "/" }
+ assert_response :redirect
+ assert_redirected_to root_path
+
+ get auth_failure_path, :params => { :origin => "http://www.google.com" }
+ assert_response :redirect
+ assert_redirected_to login_path
+ end
end