For the same reason i've done this: http://mcasimir.github.com/checkin/.
Checkin is an authorization gem that is independent from the role/authentication library you use.
You can express even complex rules rather simply with a declarative/cascading permissions DSL.
I found it very handy. The debug is also supported via the explain method that will log the authorization process on every request.
Here are some of the features:
- Handy DSL to define roles and permissions with a declarative approach
- Check authorization for CRUD operations automatically
- Standard way to rescue from Authorization errors
- Authorization subject decoupled from model (compatible with any autentication system)
- Role-based authorization decoupled from role system (compatible with any role
system)
- Decorator for current_user and other subject objects
- Scoped authorization rules
- Cascading authorization rules
- Simple: even complex authorization behaviour is understandable at glimpse and
easily predictable
- Support for controller based mass assignment protection
Here is a very simple example of the DSL:
class UserSubject < Checkin::Subject
role :guest, :alias => :anonymous do
!subject_model
end
role :logged_in, :alias => [:connected] do
!!subject_model
end
role :owner, :require => [:logged_in], :method => :own do |object|
object && ( object.respond_to?(:author) && ( subject_model == object.author ) ) || ( object.respond_to?(:owner) && ( subject_model == object.owner ) )
end
role :administrator, :require => :logged_in, :alias => :admin do
subject_model.has_role?(:administrator)
end
#
# Permissions
answered 2012-06-25T16:37:52.090