I followed this tutorial for setting Autlogic up properly. So, my site needs a form of level, like "Admin", "Moderator", "User", "Guest". So Admins can do everything, where Moderators may not can make site changes. And Users can't destroy, Upd开发者_开发知识库ate or Create.
You need an authorization framework like cancan or declarative_authorization for that.
You can check out my example project with Authlogic, Facebook Connect, declarative_authorization and user to user messaging.
http://github.com/jspooner/authlogic_cucumber_rspec_example
精彩评论