A great reminder that, if you choose to roll your own auth, you need to handle a lot of edge cases. Timing attacks are not obvious and easy to forget protecting against.
Don’t write your own, but also own it, and completely abstract it. Don’t let anything but a single file in a single shared library or service know anything at all about the underlying implementation.
[0]: https://blog.kiprosh.com/rails-7-1-adds-authenticated_by/