Commits on Oct 19, 2011
  1. refactor klass_name

Commits on Oct 17, 2011
  1. @tiegz
  2. @tiegz

    Fixing Authlogic::Session::Callbacks for new rails 3 callback system …

    tiegz authored
    …(the run_callback block serves different purpose).
    Also fixes an http_auth test that wasn't caught b/c of the callback bug (reset the persisted session when testing http auth multiple times).
Commits on May 17, 2011
  1. Merge pull request #202 from malclocke/master

    Allow use of authenticate_or_request_with_http_basic
Commits on May 1, 2011
  1. user where

Commits on Apr 30, 2011
Commits on Nov 10, 2010
  1. @brandonbloom
Commits on Nov 4, 2010
  1. @malclocke
Commits on Nov 1, 2010
  1. @benmanns
Commits on Oct 27, 2010
  1. @malclocke

    Adds support for HTTP authorization required

    malclocke authored
    Also allows setting the authentication realm.
Commits on Sep 5, 2010
Commits on Nov 12, 2009
  1. @nicolasblanco

    By default, the cookie key should be guessed from the session klass n…

    nicolasblanco authored committed
    …ame instead of the klass name. So that we don't have to change cookie keys if we have multiple session models authenticating with the same model.
Commits on Sep 12, 2009
  1. @m4n

    Add to_model method to session

    m4n authored committed
    Signed-off-by: Ben Johnson <>
Commits on Jul 22, 2009
  1. @crankharder

    added support for a custom generalized error message

    crankharder authored committed
    Added docs
    Signed-off-by: Ben Johnson <>
Commits on Jul 10, 2009
Commits on Jun 10, 2009
Commits on May 28, 2009
  1. * Fixed issue with using brute force protection AND generalize_creden…

    …tials_error_messages. Brute force protection was looking to see if there were password errors, which generalize_credentials_error_messages was obfuscating. This is all fixed now though thanks to a handy article on Microsoft ( ), method #2, it works every time.
Commits on May 4, 2009
  1. * Added the configuration option generalize_credentials_error_message…

    …s for the Authlogic::Session::Password module. This allows you to generalize your login / password errors messages as to not reveal was the problem was when authenticating. If enabled, when an invalid login is supplied it will use the same exact error message when an invalid password is supplied.
Commits on Apr 21, 2009
  1. * HTTP basic auth can now be toggled on or off. It also checks for th…

    …e existence of a standard username and password before enabling itself.
Commits on Apr 9, 2009
  1. * Add in custom find_with_email and find_with_login methods to perfor…

    …m case insensitive searches for databases that are case sensitive by default. This is only done if the :case_insensitive option for validates_uniqueness_of_login_field_options or validates_uniqueness_of_email_field_options is set to false. Which, as of this version, it is.
Commits on Apr 6, 2009
  1. * Cookies now store the record id as well, for faster lookup. Also to…

    … avoid the need to use sessions since sessions are lazily loaded in rails 2.3+
    * Add configuration option for Authlogic::ActsAsAuthentic: ignore_blank_passwords
Commits on Apr 1, 2009
  1. @avit

    Should accept symbols equally

    avit authored committed
    Signed-off-by: Ben Johnson <>
Commits on Mar 30, 2009
Commits on Mar 26, 2009
  1. Completely rewrote Authlogic::Testing, it's now called Authlogic::Tes…

    …tCase. Testing Authlogic is much easier now. Please see Authlogic::TestCase for more info.
Commits on Mar 25, 2009
  1. Fixed human_name for the model to use its own human name and not dele…

    …gate to the associated model.
Commits on Mar 24, 2009
Commits on Mar 23, 2009
  1. Reset failed_login_count if consecutive_failed_logins_limit has been …

    …exceed and the failed_login_ban_for has passed.
  2. Release v2.0

Commits on Mar 22, 2009
  1. Readd files

