I am trying to create a site that has 1 Admin and many users. The Admin has control over all of the users.
I am using:
- Rails 4.0
- Devise 3.2
- Sqlite3
I have generated a user model and followed instructions for adding an attribute to the user model using option 2. https://github.com/plataformatec/devise/wiki/How-To:-Add-an-Admin-role
In the database it sets a boolean value for admin to false. Is it secure to allow admin control from the database?
I am curious because the password is not stored in the database, but instead an encrypted string is stored.
Is there another way to create an admin? I attempted to follow option 1 but it has given me a lot of trouble.