Class: Ksef::Auth::AuthorizationPolicy

Inherits:
Object
  • Object
show all
Defined in:
lib/ksef/auth/authorization_policy.rb

Overview

The optional AuthorizationPolicy of an TokenRequest — a whitelist restricting which client IPs may use the resulting accessToken.

Its own class rather than a Hash inside TokenRequest because the schema treats it as a distinct structure with its own rules: three list kinds, each capped at ten entries, in a fixed order, wrapped in an AllowedIps element that is mandatory once the policy is present (docs/REFERENCE.md §4.1).

The IP values are deliberately not pattern-checked here. v2.1's patterns are correct and the schema will catch a malformed address, whereas v2.0's are broken outright (§14.4) — duplicating either in Ruby would mean maintaining a second, divergent source of truth for no gain.

Constant Summary collapse

MAX_IPS =
10
IP_ELEMENTS =

Ordered as the schema sequences them; the caller's Hash order is irrelevant.

{ addresses: "Ip4Address", ranges: "Ip4Range", masks: "Ip4Mask" }.freeze
IP_FIELDS =

The same three lists as JSON, for the KSeF-token flow's authorizationPolicy. Both authentication methods accept the policy; only their encodings differ, so the rules above are shared rather than restated. The OpenAPI contract caps each of these arrays at ten entries too, which independently corroborates MAX_IPS.

{ addresses: :ip4Addresses, ranges: :ip4Ranges, masks: :ip4Masks }.freeze

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(addresses: [], ranges: [], masks: []) ⇒ AuthorizationPolicy

Returns a new instance of AuthorizationPolicy.



46
47
48
49
50
51
52
# File 'lib/ksef/auth/authorization_policy.rb', line 46

def initialize(addresses: [], ranges: [], masks: [])
  @addresses = Array(addresses).freeze
  @ranges = Array(ranges).freeze
  @masks = Array(masks).freeze
  validate!
  freeze
end

Instance Attribute Details

#addresses ⇒ Object (readonly)

Returns the value of attribute addresses.



29
30
31
# File 'lib/ksef/auth/authorization_policy.rb', line 29

def addresses
  @addresses
end

#masks ⇒ Object (readonly)

Returns the value of attribute masks.



29
30
31
# File 'lib/ksef/auth/authorization_policy.rb', line 29

def masks
  @masks
end

#ranges ⇒ Object (readonly)

Returns the value of attribute ranges.



29
30
31
# File 'lib/ksef/auth/authorization_policy.rb', line 29

def ranges
  @ranges
end

Class Method Details

.coerce(value) ⇒ AuthorizationPolicy?

Returns passes nil and an existing policy through.

Returns:

Raises:



33
34
35
36
37
38
39
40
41
42
43
44
# File 'lib/ksef/auth/authorization_policy.rb', line 33

def self.coerce(value)
  return value if value.nil? || value.is_a?(self)

  unknown = value.keys - IP_ELEMENTS.keys
  unless unknown.empty?
    raise ValidationError,
          "Unknown allowed_ips key(s) #{unknown.map(&:inspect).join(", ")}. " \
          "Permitted: #{IP_ELEMENTS.keys.map(&:inspect).join(", ")}."
  end

  new(**value)
end

Instance Method Details

#empty? ⇒ Boolean

Returns:

  • (Boolean)


68
# File 'lib/ksef/auth/authorization_policy.rb', line 68

def empty? = addresses.empty? && ranges.empty? && masks.empty?

#entries ⇒ Array<Array(String, String)>

Returns [element name, value] pairs in schema order.

Returns:

  • (Array<Array(String, String)>) —

    [element name, value] pairs in schema order



55
56
57
# File 'lib/ksef/auth/authorization_policy.rb', line 55

def entries
  IP_ELEMENTS.flat_map { |key, name| public_send(key).map { |value| [name, value] } }
end

#to_h ⇒ Hash

Returns the contract's AllowedIps, omitting the lists that are empty — all three are nullable, and sending [] says nothing the absence does not.

Returns:

  • (Hash) —

    the contract's AllowedIps, omitting the lists that are empty — all three are nullable, and sending [] says nothing the absence does not



61
62
63
64
65
66
# File 'lib/ksef/auth/authorization_policy.rb', line 61

def to_h
  IP_FIELDS.each_with_object({}) do |(key, field), json|
    values = public_send(key)
    json[field] = values unless values.empty?
  end
end