Giter Site home page Giter Site logo

smart / modulr-authentication Goto Github PK

View Code? Open in Web Editor NEW

This project forked from technoweenie/restful-authentication

3.0 2.0 0.0 833 KB

Generates common user authentication code for Rails/Merb, with a full test/unit and rspec suite and optional Acts as State Machine support built-in.

Home Page: http://www.ragingonrails.com

Ruby 100.00%

modulr-authentication's Introduction

h1. Modular Restful Authentication Generator by Steve Martocci of Sympact Technologies

This fork of the widely-used plugin "restful-authentication" decouples the authenticator from the identity and allows for support of multiple authentication methods.  Think of it like this.

You are your identity and you have several ID cards to prove this identity (drivers licence, school id, etc), each one of these ID cards brings a different level of credibility as well as different levels of access.  The other great feature is the ability to support social login features like Facebook, Google Authentication, or Yahoo IDs, you can also use OpenID and Mobile Phones.  Each authenticator module has a common interface, this allows you to build your own custom authenticators.  

More Soon!

You can visit Steve's blog at www.ragingonrails.com and his company at www.sympact.net


restful-authentication readme below

This enables you to allow users to sign up using an email address, but restrict certain features of the site to those who have added a mobile pho 


h1. Restful Authentication Generator

This widely-used plugin provides a foundation for securely managing user
authentication:
* Login / logout
* Secure password handling
* Account activation by validating email
* Account approval / disabling by admin
* Rudimentary hooks for authorization and access control.

Several features were updated in May, 2008.  The newest version of this plugin
may be found in
  http://github.com/technoweenie/restful-authentication/tree/master
While a "classic" (backward-compatible) version may be found in
  http://github.com/technoweenie/restful-authentication/tree/classic

  !! important: if you upgrade your site, existing user account !!
  !! passwords will stop working unless you use --old-passwords !!

This page has notes on
* "Installation":#INSTALL
* "Compatibility Warning":#COMPATIBILITY
* "New Features":#AWESOME
* "After installing":#POST-INSTALL

See the "wiki":http://github.com/technoweenie/restful-authentication/wikis/home
(or the notes/ directory) if you want to learn more about:

* "Security Design Patterns":Security-Patterns with "snazzy diagram":http://github.com/technoweenie/restful-authentication/tree/master/notes/SecurityFramework.png
* [[Authentication]] -- Lets a visitor identify herself (and lay  claim to her corresponding Roles and measure of Trust)
* "Trust Metrics":Trustification -- Confidence we can rely on the outcomes of this visitor's actions.
* [[Authorization]] and Policy -- Based on trust and identity, what actions may this visitor perform?
* [[Access Control]] -- How the Authorization policy is actually enforced in your code (A: hopefully without turning it into  a spaghetti of if thens)
* [[Rails Plugins]] for Authentication, Trust,  Authorization and Access Control
* [[Tradeoffs]] -- for the paranoid or the curious, a rundown of tradeoffs made in the code
* [[CHANGELOG]] -- Summary of changes to internals
* [[TODO]] -- Ideas for how you can help

These best version of the release notes are in the notes/ directory in the
"source code":http://github.com/technoweenie/restful-authentication/tree/master
-- look there for the latest version.  The wiki versions are taken (manually)
from there.
  
***************************************************************************
<a id="AWESOME"/> </a>
h2. Exciting new features

h3. Stories

There are now RSpec stories that allow expressive, enjoyable tests for the
authentication code. The flexible code for resource testing in stories was
extended from "Ben Mabey's.":http://www.benmabey.com/2008/02/04/rspec-plain-text-stories-webrat-chunky-bacon/

h3. Modularize to match security design patterns:

* Authentication (currently: password, browser cookie token, HTTP basic)
* Trust metric (email validation) 
* Authorization (stateful roles)
* Leave a flexible framework that will play nicely with other access control / policy definition / trust metric plugins

h3. Other

* Added a few helper methods for linking to user pages
* Uniform handling of logout, remember_token
* Stricter email, login field validation
* Minor security fixes -- see CHANGELOG

***************************************************************************
<a id="COMPATIBILITY"/> </a>
h2. Non-backwards compatible Changes

Here are a few changes in the May 2008 release that increase "Defense in Depth"
but may require changes to existing accounts

* If you have an existing site, none of these changes are compelling enough to
  warrant migrating your userbase.
* If you are generating for a new site, all of these changes are low-impact.
  You should apply them.

h3. Passwords

The new password encryption (using a site key salt and stretching) will break
existing user accounts' passwords.  We recommend you use the --old-passwords
option or write a migration tool and submit it as a patch.  See the
[[Tradeoffs]] note for more information.

h3. Validations

By default, 

***************************************************************************
<a id="INSTALL"/> </a>
h2. Installation

This is a basic restful authentication generator for rails, taken from
acts as authenticated.  Currently it requires Rails 1.2.6 or above.

To use:

  ./script/generate authenticated user sessions \
    --include-activation \
    --stateful \
    --rspec \
    --skip-migration \
    --skip-routes \
    --old-passwords

* The first parameter specifies the model that gets created in signup (typically
  a user or account model).  A model with migration is created, as well as a
  basic controller with the create method. You probably want to say "User" here.

* The second parameter specifies the session controller name.  This is the
  controller that handles the actual login/logout function on the site.
  (probably: "Session").

* --include-activation: Generates the code for a ActionMailer and its respective
  Activation Code through email.

* --stateful: Builds in support for acts_as_state_machine and generates
  activation code.  (@--stateful@ implies @--include-activation@). Based on the
  idea at [[http://www.vaporbase.com/postings/stateful_authentication]]. Passing
  @--skip-migration@ will skip the user migration, and @--skip-routes@ will skip
  resource generation -- both useful if you've already run this generator.

* --aasm: Works the same as stateful but uses the updated aasm gem

* --rspec: Generate RSpec tests and Stories in place of standard rails tests.
  This requires the
    "RSpec and Rspec-on-rails plugins":http://rspec.info/
  (make sure you "./script/generate rspec" after installing RSpec.)  The rspec
  and story suite are much more thorough than the rails tests, and changes are
  unlikely to be backported.
  
* --old-passwords: Use the older password scheme (see [[#COMPATIBILITY]], above)

* --skip-migration: Don't generate a migration file for this model

* --skip-routes: Don't generate a resource line in @config/routes.rb@


***************************************************************************
<a id="POST-INSTALL"/> </a>
h2. After installing

The below assumes a Model named 'User' and a Controller named 'Session'; please
alter to suit. There are additional security minutae in @notes/README-Tradeoffs@
-- only the paranoid or the curious need bother, though.

* Add these familiar login URLs to your @config/routes.rb@ if you like:

     map.signup  '/signup', :controller => 'users',   :action => 'new' @
     map.login   '/login',  :controller => 'sessions', :action => 'new' @
     map.logout  '/logout', :controller => 'sessions', :action => 'destroy' @
    
* With @--include-activation@, also add to your @config/routes.rb@:
  
    map.activate '/activate/:activation_code', :controller => 'users', :action => 'activate', :activation_code => nil) 
    
  and add an observer to @config/environment.rb@:
  
    config.active_record.observers = :users_observer

* With @--stateful@, add an observer to config/environment.rb:
  
    config.active_record.observers = :user_observer
  
  and modify the users resource line to read
  
    map.resources :users, :member => { :suspend   => :put,
                                       :unsuspend => :put,
                                       :purge     => :delete } 

* If you use a public repository for your code (such as github, rubyforge,
  gitorious, etc.) make sure to NOT post your site_keys.rb (add a line like
  '/config/initializers/site_keys.rb' to your .gitignore or do the svn ignore
  dance), but make sure you DO keep it backed up somewhere safe.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.