Module: Sorcery::Controller::InstanceMethods

Defined in:
lib/sorcery/controller.rb

Instance Method Summary collapse

Instance Method Details

#auto_login(user) ⇒ Object

login a user instance

Parameters:

  • user (<User-Model>)

    the user instance.

Returns:

    • do not depend on the return value.



86
87
88
89
# File 'lib/sorcery/controller.rb', line 86

def (user)
  session[:user_id] = user.id
  @current_user = user
end

#current_userObject

attempts to auto-login from the sources defined (session, basic_auth, cookie, etc.) returns the logged in user if found, false if not (using old restful-authentication trick, nil != false).



61
62
63
# File 'lib/sorcery/controller.rb', line 61

def current_user
  @current_user ||=  ||  unless @current_user == false
end

#current_user=(user) ⇒ Object



65
66
67
# File 'lib/sorcery/controller.rb', line 65

def current_user=(user)
  @current_user = user
end

#handle_unverified_requestObject

Overwrite Rails’ handle unverified request



92
93
94
95
96
# File 'lib/sorcery/controller.rb', line 92

def handle_unverified_request
  cookies[:remember_me_token] = nil
  @current_user = nil
  super # call the default behaviour which resets the session
end

#logged_in?Boolean

Returns:

  • (Boolean)


55
56
57
# File 'lib/sorcery/controller.rb', line 55

def logged_in?
  !!current_user
end

#login(*credentials) ⇒ Object

Takes credentials and returns a user on successful authentication. Runs hooks after login or failed login.



31
32
33
34
35
36
37
38
39
40
41
42
43
44
# File 'lib/sorcery/controller.rb', line 31

def (*credentials)
  user = user_class.authenticate(*credentials)
  if user
    return_to_url = session[:return_to_url]
    reset_session # protect from session fixation attacks
    session[:return_to_url] = return_to_url
    (user)
    after_login!(user, credentials)
    current_user
  else
    after_failed_login!(credentials)
    nil
  end
end

#logoutObject

Resets the session and runs hooks before and after.



47
48
49
50
51
52
53
# File 'lib/sorcery/controller.rb', line 47

def logout
  if logged_in?
    before_logout!(current_user)
    reset_session
    after_logout!
  end
end

#not_authenticatedObject

The default action for denying non-authenticated users. You can override this method in your controllers, or provide a different method in the configuration.



78
79
80
# File 'lib/sorcery/controller.rb', line 78

def not_authenticated
  redirect_to root_path
end

#redirect_back_or_to(url, flash_hash = {}) ⇒ Object

used when a user tries to access a page while logged out, is asked to login, and we want to return him back to the page he originally wanted.



71
72
73
# File 'lib/sorcery/controller.rb', line 71

def redirect_back_or_to(url, flash_hash = {})
  redirect_to(session[:return_to_url] || url, :flash => flash_hash)
end

#require_loginObject

To be used as before_filter. Will trigger auto-login attempts via the call to logged_in? If all attempts to auto-login fail, the failure callback will be called.



22
23
24
25
26
27
# File 'lib/sorcery/controller.rb', line 22

def 
  if !logged_in?
    session[:return_to_url] = request.url if Config.save_return_to_url
    self.send(Config.not_authenticated_action) 
  end
end