devise_security_extension

An enterprise security extension for devise, trying to meet industrial standard security demands for web applications.

Features

Model modules

Installation

Add to Gemfile

gem 'devise_security_extension'

after bundle install

rails g devise_security_extension:install

for :secure_validatable you need to add

gem 'rails_email_validator'

Configuration

Devise.setup do |config|
  # Should the password expire (e.g 3.months)
  # config.expire_password_after = 3.months

  # Need 1 char of A-Z, a-z and 0-9
  # config.password_regex = /(?=.*\d)(?=.*[a-z])(?=.*[A-Z])/

  # How often save old passwords in archive
  # config.password_archiving_count = 5

  # Deny old password (true, false, count)
  # config.deny_old_passwords = true

  # captcha integration for recover form
  # config.captcha_for_recover = true

  # captcha integration for sign up form
  # config.captcha_for_sign_up = true

  # captcha integration for sign in form
  # config.captcha_for_sign_in = true

  # captcha integration for unlock form
  # config.captcha_for_unlock = true

  # security_question integration for recover form
  # this automatically enables captchas (captcha_for_recover, as fallback)
  # config.security_question_for_recover = false

  # security_question integration for unlock form
  # this automatically enables captchas (captcha_for_unlock, as fallback)
  # config.security_question_for_unlock = false

  # security_question integration for confirmation form
  # this automatically enables captchas (captcha_for_confirmation, as fallback)
  # config.security_question_for_confirmation = false

  # ==> Configuration for :expirable
  # Time period for account expiry from last_activity_at
  config.expire_after = 90.days
end

Captcha-Support

Installation

  1. add to Gemfile “gem ‘easy_captcha’”

  2. install easy_captcha “rails g easy_captcha:install”

  3. enable captcha - see “Configuration”

  4. add captcha source in the devise views for each controller you have activated

<p><%= captcha_tag %></p>
<p><%= text_field_tag :captcha %></p>

That’s it!

Schema

Password expirable

create_table :the_resources do |t|
  # other devise fields

  t.datetime :password_changed_at
end
add_index :the_resources, :password_changed_at

Password archivable

create_table :old_passwords do |t|
  t.string :encrypted_password, :null => false
  t.string :password_salt
  t.string :password_archivable_type, :null => false
  t.integer :password_archivable_id, :null => false
  t.datetime :created_at
end
add_index :old_passwords, [:password_archivable_type, :password_archivable_id], :name => :index_password_archivable

Session limitable

create_table :the_resources do |t|
  # other devise fields

  t.string :unique_session_id, :limit => 20
end

Expirable

create_table :the_resources do |t|
  # other devise fields

  t.datetime :last_activity_at
  t.datetime :expired_at
end
add_index :the_resources, :last_activity_at
add_index :the_resources, :expired_at

Security questionable

create_table :security_questions do |t|
  t.string :locale, :null => false
  t.string :name, :null => false
end

SecurityQuestion.create! locale: :de, name: 'Wie lautet der Geburstname Ihrer Mutter?'
SecurityQuestion.create! locale: :de, name: 'Wo sind sie geboren?'
SecurityQuestion.create! locale: :de, name: 'Wie lautet der Name Ihres ersten Haustieres?'
SecurityQuestion.create! locale: :de, name: 'Was ist Ihr Lieblingsfilm?'
SecurityQuestion.create! locale: :de, name: 'Was ist Ihr Lieblingsbuch?'
SecurityQuestion.create! locale: :de, name: 'Was ist Ihr Lieblingstier?'
SecurityQuestion.create! locale: :de, name: 'Was ist Ihr Lieblings-Reiseland?'

add_column :the_resources, :security_question_id, :integer
add_column :the_resources, :security_question_answer, :string

or

create_table :the_resources do |t|
  # other devise fields

  t.integer :security_question_id
  t.string :security_question_answer
end

Requirements

Todo

History

Maintainers

Contributing to devise_security_extension

Copyright © 2011-2012 Marco Scholl. See LICENSE.txt for further details.