4 ms·
Do you believe clearance is better than using the restful authentication plugin? What are the benefits/differences that you find most compelling?
by ApolloRising 17y ago
Do you believe clearance is better than using the restful authentication plugin? What are the benefits/differences that you find most compelling?
- a-priori 17y agoI've been using authlogic recently, so I'm also curious how Clearance compares to that.
- timmaah 17y agoI 2nd authlogic.. I like how it is much more unobtrusive then the others. Also has tons of options and add-ons
- brandonkm 17y agoauthlogic is great. Used it recently in an app I worked on. After doing a bit of research on all of the rails authentication options, I'm really happy I went with it.
- steveklabnik 17y agoauthlogic combined with acl9 is one of the best auth/auth solutions I've ever used.
- masomenos 17y agohttp://robots.thoughtbot.com/post/161233418/analysis-paralysis-access-control http://robots.thoughtbot.com/post/161233418/analysis-paralys... addresses this very question.
- theBobMcCormick 17y agoAnything is better than the restful authentication plugin! I haven't looked at clearance enough to be able to fairly compare/contrast it to authlogic (my current favorite), but it certainly looks promising. The restful authentication plug, on the other hand, is nasty. When you hear people talk about the evils of code generation, restful auth is the kind of thing they're talking about. What do I mean by that? The generators that come with Rails are (IMHO) good. They generate a very minimalistic skeletal structure. What they generate is small, easily understood, and easy added to/replaced by your own code as you go. All the complex gnarly pieces are in the Rails libraries, where they belong, not in the generated code. The built in Rails generators are basically the command-line equivalent of the "new class" type wizards that come with most IDE's Restful authentication, on the other hand, comes with generators that spew out massive amounts of generated code. It's not scaffolding, it's a mass one way dump of autogenerated code. Functionality that should be in a nice library where it can be easily upgrade with each new version of the framework is instead spewed out in generated model and controller code. You will then have to modify this generated code for all but the most trivial uses of restful auth, thereby ensuring you'll never have a clean way of upgrading your app to a new version of restful auth. Meaning that if there are security fixes in a newer version of restful auth, you're gonna have to be responsible to merge them into your code manually.
- jeremymcanally 17y agoI actually prefer this model of code generation to abstracting everything away into the plugin where I can't get at it. I generally do a lot of modification to code in plugins, and having it generated and hackable right away is much easier to me than having to hunt it down, hack it in the plugin, dig through the plugin's tests, fix the test there, and then hope it didn't break anything else. Of course, if you're not skilled enough to be doing that sort of modification or your apps are simple enough it doesn't call for it, then that's no win for you. But even so, to say the code that restful_auth generates is nasty either betrays your ignorance and/or shows that you tow some party line that I've never been privvy to. The code it generates is perfectly fine. It was written by Rick Olson, who (as I well know) is a fantastic developer. It doesn't support tons of extra bells and whistles like Clearance and friends, but who really needs a lot of the stuff they offer in every app? It's deadweight. In fact, depending on which branch you get of the restful_auth plugin, the code it generates abstracts stuff away in modules that you include (so you don't have to go through that oh so cumbersome maintenance you seem so caught up on) and it generates all the stuff you'd have to create by hand for Clearance.
- theBobMcCormick 17y agoInterestingly, there's a new branch (http://github.com/technoweenie/restful-authentication/tree/modular http://github.com/technoweenie/restful-authentication/tree/m...) of Restful Authentication (labeled "Experimental Branch" in the README for the main branch) that backs away from the code generation approach of the current and previous versions of Restful Auth. To quote from readme in the modular branch of Restful Authentication: "The plugin now generates much less app-space code: the controllers are super skinny now, and if any security flaws are discovered it should be less painfulto stay current." I applaud their new direction, but IMHO the fact that this is their new direction validates my point that their old direction was just plain wrong. Code generation is little different than "cut and paste" programming.
- steveklabnik 17y agoThe main problem with generators is that it makes it much harder to upgrade to a new version. Then again, if you're hacking the plugin (as you apparently have to do) you're sort of stuck anyway. I've never had to do such a thing. crosses fingers