Alex Rivera | Logout

Alternative for CanCan?

Asked 2011-08-27T10:23:36.160
30

I use rspec, devise and cancan at the moment. To be honest, I find cancan to be very confusing and I am encountering a lot difficulties in picking it up and using it effectively. The docs are not very in depth making this extremely difficult for me to debug (check my past questions).

Is there an alternative to CanCan that's also easily integratable in the other tools I am using?

Edit
Report

2 Answers

4

For the same reason i've done this: http://mcasimir.github.com/checkin/.

Checkin is an authorization gem that is independent from the role/authentication library you use.

You can express even complex rules rather simply with a declarative/cascading permissions DSL.

I found it very handy. The debug is also supported via the explain method that will log the authorization process on every request.

Here are some of the features:

  • Handy DSL to define roles and permissions with a declarative approach
  • Check authorization for CRUD operations automatically
  • Standard way to rescue from Authorization errors
  • Authorization subject decoupled from model (compatible with any autentication system)
  • Role-based authorization decoupled from role system (compatible with any role system)
  • Decorator for current_user and other subject objects
  • Scoped authorization rules
  • Cascading authorization rules
  • Simple: even complex authorization behaviour is understandable at glimpse and easily predictable
  • Support for controller based mass assignment protection

Here is a very simple example of the DSL:

class UserSubject < Checkin::Subject

      role :guest, :alias => :anonymous do
          !subject_model
      end

      role :logged_in, :alias => [:connected] do
          !!subject_model
      end

      role :owner, :require => [:logged_in], :method => :own do |object|
          object && ( object.respond_to?(:author) && ( subject_model == object.author ) ) ||  ( object.respond_to?(:owner) && ( subject_model == object.owner ) )
      end

      role :administrator, :require => :logged_in, :alias => :admin do
          subject_model.has_role?(:administrator)
      end

      #
      # Permissions
      
answered 2012-06-25T16:37:52.090
2

I am currently exploring Heimdallr. The one feature it has that most of these cancan alternatives don't are restricted scopes for index actions.

answered 2012-08-30T06:30:18.823

Your Answer