The comment said never a bypass
A password change gated on the current password, a careful comment explaining why it could not be bypassed, and a nil that walked straight past it. What Rails documents as a feature of has_secure_password, and why your request specs cannot reproduce the attack.