Doorkeeper
Devise Token Auth
Our great sponsors
Doorkeeper | Devise Token Auth | |
---|---|---|
6 | 7 | |
5,255 | 3,507 | |
0.3% | - | |
7.5 | 6.0 | |
9 days ago | 3 months ago | |
Ruby | Ruby | |
MIT License | Do What The F*ck You Want To Public License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Doorkeeper
-
Best way for user auth with a Rails API?
The doorkeeper gem.
-
Rails Personal access tokens
Take a look at doorkeeper.
-
Zitadel: The best of Auth0 and Keycloak combined
Disclosure: I work for FusionAuth.
Depends on what you are looking for.
If you want a standalone auth server, you can use FusionAuth in docker/docker-compose: https://fusionauth.io/docs/v1/tech/installation-guide/docker
You can also package up a library; most major languages have one or more OAuth/OIDC libraries: https://github.com/doorkeeper-gem/doorkeeper for Ruby, https://spring.io/projects/spring-security for Spring/Java, https://oauth2.thephpleague.com/ for PHP, https://pypi.org/project/oauthlib/ for Python.
https://oauth.net/code/ has a further selection of libraries in a variety of languages.
-
Need help implementing PKCE flow in Doorkeeper
Are there any code examples to implement the PKCE flow in Doorkeeper? I am a bit confused on how to implement it here: https://github.com/doorkeeper-gem/doorkeeper/wiki/Using-PKCE-flow
-
Using the same backend for both web views & mobile app
For authorization we use Doorkeeper gem with PKCE flow.
-
Authelia is an open-source authentication/authorization server with 2FA/SSO
One thing that is missing from this list is open source language specific libraries. Projects such as https://oauthlib.readthedocs.io/en/latest/oauth2/server.html and https://github.com/doorkeeper-gem/doorkeeper
Depending on your use case, for example if you only have one application, you might be better off running something embedded in your app, or independent but using the same runtime/deployment environment. Then, when you are ready to add another app or integration, you should be able to introduce a standalone auth system more easily if appropriate (because all your auth interactions should be relatively standardized). I'm a big fan of standalone auth systems as a way to simplify access control and give a single view of a user/customer, but you can also succeed using open source embedded libraries.
When the moment comes to introduce a standalone system, you should consider a few dimensions (this list pulled from a previous comment of mine: https://news.ycombinator.com/item?id=26360048 ):
* open source or not
Devise Token Auth
-
Managing redirects to a subdomain after authentication in a React/Rails application using React Router
I have a React single page application using React Router that hooks into a Rails 5 API. The Rails application uses devise_token_auth for authentication. I've successfully created an authentication process that stores the user state in a Redux store on the client side.
-
Is it possible to retrieve the user index with devise ?
Did you send an authorization header with your api call? The error is pretty clear — the request is unauthorized. Devise is expecting session cookies, but your api should use tokens. https://github.com/lynndylanhurley/devise_token_auth
-
Don't make me think, or why I switched to Rails from JavaScript SPAs
I mentioned Identity in my first comment. I've never found it as simple as Devise though - especially in an API only setting.
With Devise there's a third-party Gem you can use called devise_token_auth which deals with everything automatically.
https://github.com/lynndylanhurley/devise_token_auth
-
Working around un-maintained redux-token-auth for redux and react 17 upgrade
redux-token-auth is a great library. What it mainly does is it provides a plug and play auth implementation functionality for ruby on rails based APIs which implement popular devise_token_auth for auth handling.
-
Rails API Authentication with JWT Options
have you looked at https://github.com/waiting-for-dev/devise-jwt or https://github.com/lynndylanhurley/devise_token_auth
-
Best project setup for Rails+React with "remember me" feature
I'd prefer to have a standalone rails API and a react client separately, but that's not mandatory. I discovered a gem called devise_token_auth and it didn't seem to have refresh tokens but it refreshed the tokens on every request anyway so I was pretty happy with it.
-
Devise, The Swiss Army Knife of Rails User Authentication.
As a side note, also check out devise_token_auth here
What are some alternatives?
OmniAuth - OmniAuth is a flexible authentication system utilizing Rack middleware.
JWT - A ruby implementation of the RFC 7519 OAuth JSON Web Token (JWT) standard.
Devise - Flexible authentication solution for Rails with Warden.
devise-jwt - JWT token authentication with devise and rails
OAuth2 - A Ruby wrapper for the OAuth 2.0 protocol.
Knock - Seamless JWT authentication for Rails API
warden - General Rack Authentication Framework
openapi-typescript-codegen - NodeJS library that generates Typescript or Javascript clients based on the OpenAPI specification