3 ms·
After many years of Rails (and other frameworks), I know now that I NEED to review the code of plugins written by folks smarter than you or I. I don't count the
by mickeyben 16y ago
After many years of Rails (and other frameworks), I know now that I NEED to review the code of plugins written by folks smarter than you or I. I don't count the times I had to remove plugins from my application.
I use Warden and saw there was a rememberable strategy in Devise that I could use.
I also read I can secure the cookies to be only send over SSL. I was hoping some further explanations on that since Devise doesn't seem to do it.
- angelbob 16y agoThat's true. And yes, devise doesn't do that by default. Basically, you'll want to have Devise (or better yet, all of Rails) set to only use secure cookies. Unfortunately, most Rails apps run without SSL, so that's not going to be the default any year soon. At this point, you really do have to pay money for a good SSL certificate, or self-sign and then people have to click through an ominous-looking dialog to use your site.