Two-factor Authentication with Rails
moocode.com
moocode.com
Also, why does this implementation needs its own special cookie? Why not just do the (minimal) housekeeping this requires in the Rails session? Magic cookies are usually a code smell.
This uses another cookie because it is permanent. The standard rails session cookie ends at the end of the session so isn't acceptable here.