Class: OmniAuth::Strategies::OAuth2
- Inherits:
-
Object
- Object
- OmniAuth::Strategies::OAuth2
- Includes:
- OmniAuth::Strategy
- Defined in:
- lib/omniauth/strategies/oauth2.rb
Overview
Authentication strategy for connecting with APIs constructed using the [OAuth 2.0 Specification](tools.ietf.org/html/draft-ietf-oauth-v2-10). You must generally register your application with the provider and utilize an application id and secret in order to authenticate using OAuth 2.0.
Defined Under Namespace
Classes: CallbackError
Instance Attribute Summary collapse
-
#access_token ⇒ Object
Returns the value of attribute access_token.
Class Method Summary collapse
Instance Method Summary collapse
- #authorize_params ⇒ Object
-
#callback_phase ⇒ Object
rubocop:disable AbcSize, CyclomaticComplexity, MethodLength, PerceivedComplexity.
- #client ⇒ Object
- #request_phase ⇒ Object
- #token_params ⇒ Object
Instance Attribute Details
#access_token ⇒ Object
Returns the value of attribute access_token.
33 34 35 |
# File 'lib/omniauth/strategies/oauth2.rb', line 33 def access_token @access_token end |
Class Method Details
.inherited(subclass) ⇒ Object
17 18 19 |
# File 'lib/omniauth/strategies/oauth2.rb', line 17 def self.inherited(subclass) OmniAuth::Strategy.included(subclass) end |
Instance Method Details
#authorize_params ⇒ Object
51 52 53 54 55 56 57 58 59 60 |
# File 'lib/omniauth/strategies/oauth2.rb', line 51 def .[:state] = SecureRandom.hex(24) params = ..merge(("authorize")) if OmniAuth.config.test_mode @env ||= {} @env["rack.session"] ||= {} end session["omniauth.state"] = params[:state] params end |
#callback_phase ⇒ Object
rubocop:disable AbcSize, CyclomaticComplexity, MethodLength, PerceivedComplexity
66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 |
# File 'lib/omniauth/strategies/oauth2.rb', line 66 def callback_phase # rubocop:disable AbcSize, CyclomaticComplexity, MethodLength, PerceivedComplexity error = request.params["error_reason"] || request.params["error"] if error fail!(error, CallbackError.new(request.params["error"], request.params["error_description"] || request.params["error_reason"], request.params["error_uri"])) elsif !.provider_ignores_state && (request.params["state"].to_s.empty? || request.params["state"] != session.delete("omniauth.state")) fail!(:csrf_detected, CallbackError.new(:csrf_detected, "CSRF detected")) else self.access_token = build_access_token self.access_token = access_token.refresh! if access_token.expired? super end rescue ::OAuth2::Error, CallbackError => e fail!(:invalid_credentials, e) rescue ::Timeout::Error, ::Errno::ETIMEDOUT => e fail!(:timeout, e) rescue ::SocketError => e fail!(:failed_to_connect, e) end |
#client ⇒ Object
35 36 37 |
# File 'lib/omniauth/strategies/oauth2.rb', line 35 def client ::OAuth2::Client.new(.client_id, .client_secret, deep_symbolize(.)) end |
#request_phase ⇒ Object
47 48 49 |
# File 'lib/omniauth/strategies/oauth2.rb', line 47 def request_phase redirect client.auth_code.({:redirect_uri => callback_url}.merge()) end |
#token_params ⇒ Object
62 63 64 |
# File 'lib/omniauth/strategies/oauth2.rb', line 62 def token_params .token_params.merge(("token")) end |