
Authorization on rails
The Stack Overflow Podcast
00:00
What Would It Look Like if Authorization Had a Rails Equivalent?
Rails is very opinionated about how you build a web app and it's got a lot of built in conventions. So that was kind of like the challenge we put to ourselves: What would it look like if authorization had an opinionated version? OAuth spec is very much not opinionated, so what would be the opinionated version?" "I think the simplest differentiator I've heard is that authentication is who are you and authorization is should you be here?""We have our own framework for thinking about it," he says. 'One is data, two is logic, three is enforcement'
Transcript
Play full episode