Certainly. There is another position that needs to be addressed: HTTPS delivers defense in opposition to destructive page modification. Return a boolean from the authorize method to tell the validator whether to forward the ask for for the controller. Then register to the account and head over to "my profile". http://alexisashxm.jaiblogs.com/17491095/validation-toto-site-for-dummies