Authority has been great for us so far, as we have lots of things to authorize we really like the fact that you can define authorizer classes for each type of resource. It lets you define common behaviors and then build complex rules for some resources if needed.

One drawback of Authority is that it is a one way street, it let's you say: can user read this document? but it doesn't try to do something like: give me all the documents that this user can read. I think that cancan tries to do this.

It also doesn't deal with restricting access to particular attributes.

Sebastian

Tim Uckun <mailto:[email protected]>
22 February 2013 11:09 AM
I saw this the other day
http://bizarre-authorization.talks.makandra.com/ and it was quite
interesting. It uses two gems I hadn't heard of before Consul and
assignable_values. CanCan is able to do a lot of that but not
everything. Authority gem is also nice.

What have you guys used when you needed complex and seemingly insane
Authorization schemes? Has CanCan been enough for everybody?


--
You received this message because you are subscribed to the Google Groups "Ruby or 
Rails Oceania" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at http://groups.google.com/group/rails-oceania?hl=en.
For more options, visit https://groups.google.com/groups/opt_out.


<<inline: postbox-contact.jpg>>

Reply via email to