← Back
Rails 8 authentication replaces Devise
New
Jumpstart Pro now uses Rails' built-in authentication instead of Devise. Pretender and Pundit are also gone, replaced by an Impersonation concern and simple role guards. Authentication now works the way Rails generates it: plain code in your app that's easy to read and change.
What still works
- Existing passwords. Devise's bcrypt digests still verify, so nobody needs to reset.
- Two-factor authentication, OAuth providers, and impersonation.
- Old Devise sign in, sign up, and password URLs redirect to the new pages.
What your users will notice
- Everyone is signed out once when you deploy.
- Password reset links sent before the deploy stop working.
- The "Remember me" checkbox is gone because sessions are always persistent.
Breaking changes
Authentication is now required by default. Use allow_unauthenticated_access to make actions public. Helpers have been renamed too, for example authenticate_user! is now require_authentication and user_signed_in? is now authenticated?. UPGRADE.md has step-by-step instructions and a script that does the renames for you.