Rails With Devise Api Gem

August 29, 2024

Installing Gems

Assuming you have an existing Rails API, run the following commands in the terminal:

bundle add devise devise-api

rails g devise:install && rails g devise user

rails g devise_api:install

Configure Cors

# Gemfile
gem 'rack-cors'

Modify cors.rb

# config/initializers/cors.rb

# Be sure to restart your server when you modify this file.

# Avoid CORS issues when API is called from the frontend app.
# Handle Cross-Origin Resource Sharing (CORS) in order to accept cross-origin Ajax requests.

# Read more: https://github.com/cyu/rack-cors

Rails.application.config.middleware.insert_before 0, Rack::Cors do
  allow do
    origins "*"

    resource "*",
      headers: :any,
      methods: [:get, :post, :put, :patch, :delete, :options, :head]

Create Controller class as follows

class ImagesController < ApplicationController
  before_action :authenticate_devise_api_token!, only: [:create]

  def index; end

  def create
    devise_api_token = current_devise_api_token

    if devise_api_token
      render json: { message: "You are logged in as #{devise_api_token.resource_owner.email}" }, status: :ok
      render json: { message: 'You are not logged in' }, status: :unauthorized

Modify the User Model

class User < ApplicationRecord
  # Include default devise modules. Others available are:
  # :confirmable, :lockable, :timeoutable, :trackable and :omniauthable
  devise :database_authenticatable, :registerable,
         :recoverable, :rememberable, :validatable, :api #add this


Hit the following routes using Postman:


POST http://localhost:3000/users/tokens/sign_up
Content-Type: application/json

    "email": "mary.sawyer@gmail.com",
    "password": "password123&"



POST http://localhost:3000/users/tokens/sign_in
Content-Type: application/json

    "email": "mary.sawyer@gmail.com",
    "password": "password123&"


Protected Route:

POST http://localhost:3000/images
Content-Type: application/json
Authorization: Bearer QL4sqV4Q7-yZcAKvmaxVCYqsBaHwpw81Jks2sk5mKjPiijxG5jJsuki7JBtU

    "image": "image"

For further information regarding the available authentication routes: seeDevise Api documentation

Written by Marylene Sawyer is a web developer dedicated to building useful and impactful solutions. With a passion for technology and creativity, she enjoys crafting applications that enhance user experiences. Marylene combines her technical expertise with a keen eye for design, striving to create intuitive and engaging interfaces that meet the needs of users.