Class: Ksef::Auth::AuthorizationPolicy
- Inherits:
-
Object
- Object
- Ksef::Auth::AuthorizationPolicy
- Defined in:
- lib/ksef/auth/authorization_policy.rb
Overview
The optional AuthorizationPolicy of an TokenRequest — a whitelist restricting
which client IPs may use the resulting accessToken.
Its own class rather than a Hash inside TokenRequest because the schema treats it
as a distinct structure with its own rules: three list kinds, each capped at ten
entries, in a fixed order, wrapped in an AllowedIps element that is mandatory once
the policy is present (docs/REFERENCE.md §4.1).
The IP values are deliberately not pattern-checked here. v2.1's patterns are correct and the schema will catch a malformed address, whereas v2.0's are broken outright (§14.4) — duplicating either in Ruby would mean maintaining a second, divergent source of truth for no gain.
Constant Summary collapse
- MAX_IPS =
10- IP_ELEMENTS =
Ordered as the schema sequences them; the caller's Hash order is irrelevant.
{ addresses: "Ip4Address", ranges: "Ip4Range", masks: "Ip4Mask" }.freeze
- IP_FIELDS =
The same three lists as JSON, for the KSeF-token flow's
authorizationPolicy. Both authentication methods accept the policy; only their encodings differ, so the rules above are shared rather than restated. The OpenAPI contract caps each of these arrays at ten entries too, which independently corroborates MAX_IPS. { addresses: :ip4Addresses, ranges: :ip4Ranges, masks: :ip4Masks }.freeze
Instance Attribute Summary collapse
-
#addresses ⇒ Object
readonly
Returns the value of attribute addresses.
-
#masks ⇒ Object
readonly
Returns the value of attribute masks.
-
#ranges ⇒ Object
readonly
Returns the value of attribute ranges.
Class Method Summary collapse
-
.coerce(value) ⇒ AuthorizationPolicy?
Passes
niland an existing policy through.
Instance Method Summary collapse
- #empty? ⇒ Boolean
-
#entries ⇒ Array<Array(String, String)>
[element name, value]pairs in schema order. -
#initialize(addresses: [], ranges: [], masks: []) ⇒ AuthorizationPolicy
constructor
A new instance of AuthorizationPolicy.
-
#to_h ⇒ Hash
The contract's
AllowedIps, omitting the lists that are empty — all three are nullable, and sending[]says nothing the absence does not.
Constructor Details
#initialize(addresses: [], ranges: [], masks: []) ⇒ AuthorizationPolicy
Returns a new instance of AuthorizationPolicy.
46 47 48 49 50 51 52 |
# File 'lib/ksef/auth/authorization_policy.rb', line 46 def initialize(addresses: [], ranges: [], masks: []) @addresses = Array(addresses).freeze @ranges = Array(ranges).freeze @masks = Array(masks).freeze validate! freeze end |
Instance Attribute Details
#addresses ⇒ Object (readonly)
Returns the value of attribute addresses.
29 30 31 |
# File 'lib/ksef/auth/authorization_policy.rb', line 29 def addresses @addresses end |
#masks ⇒ Object (readonly)
Returns the value of attribute masks.
29 30 31 |
# File 'lib/ksef/auth/authorization_policy.rb', line 29 def masks @masks end |
#ranges ⇒ Object (readonly)
Returns the value of attribute ranges.
29 30 31 |
# File 'lib/ksef/auth/authorization_policy.rb', line 29 def ranges @ranges end |
Class Method Details
.coerce(value) ⇒ AuthorizationPolicy?
Returns passes nil and an existing policy through.
33 34 35 36 37 38 39 40 41 42 43 44 |
# File 'lib/ksef/auth/authorization_policy.rb', line 33 def self.coerce(value) return value if value.nil? || value.is_a?(self) unknown = value.keys - IP_ELEMENTS.keys unless unknown.empty? raise ValidationError, "Unknown allowed_ips key(s) #{unknown.map(&:inspect).join(", ")}. " \ "Permitted: #{IP_ELEMENTS.keys.map(&:inspect).join(", ")}." end new(**value) end |
Instance Method Details
#empty? ⇒ Boolean
68 |
# File 'lib/ksef/auth/authorization_policy.rb', line 68 def empty? = addresses.empty? && ranges.empty? && masks.empty? |
#entries ⇒ Array<Array(String, String)>
Returns [element name, value] pairs in schema order.
55 56 57 |
# File 'lib/ksef/auth/authorization_policy.rb', line 55 def entries IP_ELEMENTS.flat_map { |key, name| public_send(key).map { |value| [name, value] } } end |
#to_h ⇒ Hash
Returns the contract's AllowedIps, omitting the lists that are empty —
all three are nullable, and sending [] says nothing the absence does not.
61 62 63 64 65 66 |
# File 'lib/ksef/auth/authorization_policy.rb', line 61 def to_h IP_FIELDS.each_with_object({}) do |(key, field), json| values = public_send(key) json[field] = values unless values.empty? end end |