← Back

Rails 8 authentication replaces Devise

New

Jumpstart Pro now uses Rails' built-in authentication instead of Devise. Pretender and Pundit are also gone, replaced by an Impersonation concern and simple role guards. Authentication now works the way Rails generates it: plain code in your app that's easy to read and change.

What still works

  • Existing passwords. Devise's bcrypt digests still verify, so nobody needs to reset.
  • Two-factor authentication, OAuth providers, and impersonation.
  • Old Devise sign in, sign up, and password URLs redirect to the new pages.

What your users will notice

  • Everyone is signed out once when you deploy.
  • Password reset links sent before the deploy stop working.
  • The "Remember me" checkbox is gone because sessions are always persistent.

Breaking changes

Authentication is now required by default. Use allow_unauthenticated_access to make actions public. Helpers have been renamed too, for example authenticate_user! is now require_authentication and user_signed_in? is now authenticated?. UPGRADE.md has step-by-step instructions and a script that does the renames for you.