-
Notifications
You must be signed in to change notification settings - Fork 8
User Account Management
The requirement to manage user accounts (including authentication and authorization) is a given for most applications. We provide authentication, authorization and an admin page for adding/editing/deleting users.
Authentication is implemented using Devise, the most popular Ruby gem for this purpose.
Although we are developing a single page application, the entire Devise workflow is, after weighing the pros and cons, deliberately kept outside of Angular. That is, the authentication views are fully server-rendered ones. See here for a detailed discussion; note however that our implementation is different.
Relevant files in our implementation are:
- /app/controllers/application_controller (the 'set_sign_in_redirect' method)
- /app/assets/javascripts/shared/angular/directives/authentication_links.js
- All devise related files, of course
However, certain points of integration between the Rails and Angular code are required, such as accessing the current user from within Angular, and redirecting to the sign-in page for access controlled Angular routes.
In the Angular code, the currently signed in user details are available via the AuthSvc service. We have also provided helper methods to control access to certain routes, in the ROUTE_UTILS constant. See the following for more details:
- /app/assets/javascripts/shared/angular/services/auth_svc.js
- /app/assets/javascripts/shared/angular/modules/route_utils/constants/route_utils_const.js
- /app/assets/javascripts/client/angular/routes.js (search for 'R.' and 'ROUTE_UTILS')
We also provide authentication with Facebook and Google out of the box, as well as easy integration with other providers such as Twitter and more.
See the Advanced Setup page for how to enable Facebook/Google authentication.
See the Devise wiki for how to integrate other providers. This is to be done along the same lines as integrating Facebook and Google, and since we provide these two integrations out of the box, much of the code required therein is already present. The relevant files are:
Out of the box, we provide settings via the 'App Settings' menu item in the admin console to do the following:
- Disable user registration (i.e. force user accounts to be created upon request by admins only)
- Force users to sign in before they can access the app at all
We provide role-based authorization.
In the Rails code, this is done via two gems:
In the Angular code, a little library is provided that lets you define which roles can access which routes. For simple logic, this should suffice. For more complex logic, this library provides a way to check authorization from the server before allowing a route to be accessed. The relevant files are: