Ask HN: Authentication with Angular/Rails?
I know there are many companies developing with Angular and Rails (and many looking to hire for this as well).
How are you managing authentication (securely)?
How are you managing authentication (securely)?
(Afaik most Rails projects use https://github.com/plataformatec/devise/ which takes care of database setup, password hashes, session cookies, even forgot-password feature and Facebook/Twitter/Google+ logins.)
You can do token authentication, basic authentication, OAuth, OAuth2, or even roll your own. For a rails api <-> angular combo, I usually stick to token or OAuth 1/2 authentication.
I have open sourced an angular application (technically ionic but it uses angular under the hood) and the rails api that it uses as a backend which uses token authentication. https://github.com/johnkelly/mojave https://github.com/johnkelly/kalahari
Disclaimer: I'm the author.