Class: CloudKit::OpenIDFilter

Inherits:
Object
  • Object
show all
Includes:
Util
Defined in:
lib/cloudkit/openid_filter.rb

Overview

An OpenIDFilter provides OpenID authentication, listening for upstream OAuth authentication and bypassing if already authorized.

The root URI, “/”, is always bypassed. More URIs can also be bypassed using the :allow option:

use Rack::Session::Pool
use OpenIDFilter, :allow => ['/foo', '/bar']

In addition to the :allow option, a block can also be used for more complex decisions:

use Rack::Session::Pool
use OpenIDFilter, :allow => ['/foo'] do |url|
  bar(url) # some method returning true or false
end

Responds to the following URIs:

/login
/logout
/openid_complete

Constant Summary collapse

@@lock =
Mutex.new
@@store =
nil

Instance Method Summary collapse

Methods included from Util

#erb, #r, #unquote

Constructor Details

#initialize(app, options = {}, &bypass_route_callback) ⇒ OpenIDFilter

Returns a new instance of OpenIDFilter.



31
32
33
34
35
# File 'lib/cloudkit/openid_filter.rb', line 31

def initialize(app, options={}, &bypass_route_callback)
  @app     = app
  @options = options
  @bypass_route_callback = bypass_route_callback || Proc.new {|url| url == '/'}
end

Instance Method Details

#allow?(uri) ⇒ Boolean

Returns:

  • (Boolean)


225
226
227
228
# File 'lib/cloudkit/openid_filter.rb', line 225

def allow?(uri)
  @bypass_route_callback.call(uri) || 
    @options[:allow] && @options[:allow].include?(uri)
end

#base_url(request) ⇒ Object



164
165
166
# File 'lib/cloudkit/openid_filter.rb', line 164

def base_url(request)
  "#{request.scheme}://#{request.env['HTTP_HOST']}/"
end

#begin_openid_login(request) ⇒ Object



95
96
97
98
99
100
101
102
103
104
105
# File 'lib/cloudkit/openid_filter.rb', line 95

def (request)
  begin
    response = openid_consumer(request).begin(request[:openid_url])
  rescue => e
    request.flash[:error] = e
    return (request)
  end

  redirect_url = response.redirect_url(base_url(request), full_url(request))
  Rack::Response.new([], 302, {'Location' => redirect_url}).finish
end

#bypass?(request) ⇒ Boolean

Returns:

  • (Boolean)


230
231
232
233
234
# File 'lib/cloudkit/openid_filter.rb', line 230

def bypass?(request)
  allow?(request.path_info) ||
    valid_auth_key?(request) ||
    logged_in?(request)
end

#call(env) ⇒ Object



37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
# File 'lib/cloudkit/openid_filter.rb', line 37

def call(env)
  @@lock.synchronize do
    @@store = OpenIDStore.new
    @users  = UserStore.new
  end unless @@store

  request = Request.new(env)
  request.announce_auth(CLOUDKIT_OPENID_FILTER_KEY)

  case request
  when r(:get, request.); (request)
  when r(:post, request.); (request)
  when r(:get, '/openid_complete'); (request)
  when r(:post, request.logout_url); logout(request)
  else
    if bypass?(request)
      @app.call(env)
    else
      if request.env[CLOUDKIT_AUTH_CHALLENGE]
        store_location(request)
        erb(
          request,
          :openid_login,
          request.env[CLOUDKIT_AUTH_CHALLENGE].merge('Content-Type' => 'text/html'),
          401)
      elsif !request.via.include?(CLOUDKIT_OAUTH_FILTER_KEY)
        store_location(request)
        (request)
      else
        Rack::Response.new('server misconfigured', 500).finish
      end
    end
  end
end

#complete_openid_login(request) ⇒ Object



107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
# File 'lib/cloudkit/openid_filter.rb', line 107

def (request)
  begin
    idp_response = openid_consumer(request).complete(request.params, full_url(request))
  rescue => e
    request.flash[:error] = e
    return (request)
  end

  if idp_response.is_a?(OpenID::Consumer::FailureResponse)
    request.flash[:error] = idp_response.message
    return (request)
  end

  result = @users.get(
    '/cloudkit_users',
    # '/cloudkit_login_view',
    :identity_url => idp_response.endpoint.claimed_id)
  user_uris = result.parsed_content['uris']

  if user_uris.empty?
    json     = JSON.generate(:identity_url => idp_response.endpoint.claimed_id)
    result   = @users.post('/cloudkit_users', :json => json)
    user_uri = result.parsed_content['uri']
  else
    user_uri = user_uris.first
  end
  user_result = @users.resolve_uris([user_uri]).first
  user        = user_result.parsed_content

  if request.session['user_uri'] = user_uri
    request.current_user = user_uri
    user['remember_me_expiration'] = two_weeks_from_now
    user['remember_me_token'] = Base64.encode64(
      OpenSSL::Random.random_bytes(32)).gsub(/\W/,'')
    url      = request.session.delete('return_to')
    response = Rack::Response.new(
      [],
      302,
      {'Location' => (url || '/'), 'Content-Type' => 'text/html'})
    response.set_cookie(
      'remember_me', {
        :value   => user['remember_me_token'],
        :expires => Time.at(user['remember_me_expiration']).utc})
    json = JSON.generate(user)
    @users.put(user_uri, :etag => user_result.etag, :json => json)
    request.flash[:notice] = 'You have been logged in.'
    response.finish
  else
    request.flash[:error] = 'Could not log on with your OpenID.'
    (request)
  end
end

#full_url(request) ⇒ Object



168
169
170
# File 'lib/cloudkit/openid_filter.rb', line 168

def full_url(request)
  base_url(request) + 'openid_complete'
end

#logged_in?(request) ⇒ Boolean

Returns:

  • (Boolean)


172
173
174
175
176
# File 'lib/cloudkit/openid_filter.rb', line 172

def logged_in?(request)
  logged_in = user_in_session?(request) || valid_remember_me_token?(request)
  request.current_user = request.session['user_uri'] if logged_in
  logged_in
end

#login_redirect(request) ⇒ Object



160
161
162
# File 'lib/cloudkit/openid_filter.rb', line 160

def (request)
  Rack::Response.new([], 302, {'Location' => request.}).finish
end

#logout(request) ⇒ Object



72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
# File 'lib/cloudkit/openid_filter.rb', line 72

def logout(request)
  user_uri = request.session.delete('user_uri')
  result   = @users.get(user_uri)
  user     = result.parsed_content
  user.delete('remember_me_token')
  user.delete('remember_me_expiration')
  json = JSON.generate(user)
  @users.put(user_uri, :etag => result.etag, :json => json)

  request.env[CLOUDKIT_AUTH_KEY] = nil
  request.flash['info'] = 'You have been logged out.'
  response = Rack::Response.new(
    [],
    302,
    {'Location' => request., 'Content-Type' => 'text/html'})
  response.delete_cookie('remember_me')
  response.finish
end

#openid_consumer(request) ⇒ Object



194
195
196
197
# File 'lib/cloudkit/openid_filter.rb', line 194

def openid_consumer(request)
  @openid_consumer ||= OpenID::Consumer.new(
    request.session, OpenIDStore.new)
end

#request_login(request) ⇒ Object



91
92
93
# File 'lib/cloudkit/openid_filter.rb', line 91

def (request)
  erb(request, :openid_login)
end

#root_request?(request) ⇒ Boolean

Returns:

  • (Boolean)


186
187
188
# File 'lib/cloudkit/openid_filter.rb', line 186

def root_request?(request)
  request.path_info == '/' || request.path_info == '/favicon.ico'
end

#store_location(request) ⇒ Object



182
183
184
# File 'lib/cloudkit/openid_filter.rb', line 182

def store_location(request)
  request.session['return_to'] = request.url
end

#two_weeks_from_nowObject



221
222
223
# File 'lib/cloudkit/openid_filter.rb', line 221

def two_weeks_from_now
  Time.now.to_i+1209600
end

#user_in_session?(request) ⇒ Boolean

Returns:

  • (Boolean)


178
179
180
# File 'lib/cloudkit/openid_filter.rb', line 178

def user_in_session?(request)
  request.session['user_uri'] != nil
end

#valid_auth_key?(request) ⇒ Boolean

Returns:

  • (Boolean)


190
191
192
# File 'lib/cloudkit/openid_filter.rb', line 190

def valid_auth_key?(request)
  request.env[CLOUDKIT_AUTH_KEY] && request.env[CLOUDKIT_AUTH_KEY] != ''
end

#valid_remember_me_token?(request) ⇒ Boolean

Returns:

  • (Boolean)


199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
# File 'lib/cloudkit/openid_filter.rb', line 199

def valid_remember_me_token?(request)
  return false unless token = request.cookies['remember_me']

  # result = @users.get('/cloudkit_login_view', :remember_me_token => token)
  result = @users.get('/cloudkit_users', :remember_me_token => token)
  return false unless result.status == 200

  user_uris = result.parsed_content['uris']
  return false unless user_uris.try(:size) == 1

  user_uri    = user_uris.first
  user_result = @users.resolve_uris([user_uri]).first
  user        = user_result.parsed_content
  return false unless Time.now.to_i < user['remember_me_expiration']

  user['remember_me_expiration'] = two_weeks_from_now
  json = JSON.generate(user)
  @users.put(user_uri, :etag => user_result.etag, :json => json)
  request.session['user_uri'] = user_uri
  true
end