My team's project is currently using Devise's DatabaseAuthenticatable strategy to authenticate our User model. We would like to add an additional "secret key" strategy as well.
The Usermodel should authenticate using either one of these strategies depending on the provided credentials.
We found Devise::TokenAuthenticatable, which appears to have been extracted from Devise and contains the type of authentication we're looking to do. However, this gem does not appear to encrypt or salt tokens when storing them, so we figured we'd have to write our own custom strategy.
My questions:
- Is there a way to have Devise automatically pick the strategy? Can we employ both strategies on the same model?
- Is there anything we're not considering with our custom strategy approach? Is there a better way to accomplish this goal?