Authentication is a special part of web applications. On the one hand, it usually is a crucial security mechanism restrict access to certain people and roles. On the other hand, most users authenticate only once, so it is very unlikely to spot issues by accident.
So, here comes a quick checklist to help you verifying your authentication solution is all set.
rake routes
.There are a lot of footguns with authentication when an app is old or has homegrown crypto. See our guide for fixing authentication in legacy apps