class ApplicationController < ActionController::Base
include SessionPersistence
+ check_authorization
protect_from_forgery :with => :exception
raise
end
+ rescue_from CanCan::AccessDenied do |exception|
+ raise "Access denied on #{exception.action} #{exception.subject.inspect}"
+ # ...
+ end
+
private
# extract authorisation credentials from headers, returns user = nil if none