Class: ActingFor::Internal::DelegationCreator

Inherits:
Object
  • Object
show all
Defined in:
app/services/acting_for/internal/delegation_creator.rb

Class Method Summary collapse

Class Method Details

.call(agent:, principal:, action:, resource:, constraints:, effect:, expires_at:) ⇒ Object



5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
# File 'app/services/acting_for/internal/delegation_creator.rb', line 5

def call(agent:, principal:, action:, resource:, constraints:, effect:, expires_at:)
  unless agent.is_a?(ActingFor::Agent) && agent.persisted?
    raise InvalidRequestError, "agent must be a persisted ActingFor::Agent"
  end
  unless principal.is_a?(ActiveRecord::Base) && principal.persisted?
    raise InvalidRequestError, "principal must be a persisted ActiveRecord record"
  end

  action = string_value(action, "action")
  raise InvalidRequestError, "action must not be blank" if action.blank?

  resource_type, resource_id = resource_identity(resource)
  effect = string_value(effect, "effect")
  unless %w[allow require_approval].include?(effect)
    raise InvalidRequestError, "effect must be allow or require_approval"
  end

  constraints = canonical_constraints(constraints)
  validate_expiration(expires_at)

  ActingFor::Delegation.create!(
    agent: agent, principal: principal, action: action,
    resource_type: resource_type, resource_id: resource_id,
    constraints: constraints, effect: effect,
    expires_at: expires_at, revoked_at: nil
  )
end