Restrict attributes in to_xml

http://www.railsmanual.org/module/ActiveRecord%3A%3AXmlSerialization/to_xml

@user.to_xml(:except => :pw_hash, :pw_salt)