I’ll probably regret asking, but what are people’s preferred #ruby #authentication gems these days?
I’ve used but hated #devise. Have no opinions on #clearance. Really enjoyed #sorcery but it seems like there’s a v1 rewrite happening which I am always suspicious of. I have been reading up on #rodauth but since this is going to be a #rails app I’m hesitant to jam #roda into it. And does the answer change for an api-only app?
The answer is to suck it up and use devise isn’t it?
@jcn If I was starting from scratch I would probably outsource to a service like auth0. Authentication is constantly changing and getting more complex (password, 2fa, saml, oauth, oidc, webauthn,...). No matter what gem you use you'll be constantly messing with it for the life of your app, catching up to new standards, etc rather than working on the fun parts.