Class: AdminSuite::Auth::HostUser

Inherits:
Strategy
  • Object
show all
Defined in:
lib/admin_suite/auth/host_user.rb

Overview

Authenticates against the host application's own user.

This is the standard strategy and the one the docs lead with: most adopters already have a users table with a role, or a separate admin/developer user type. HTTP Basic and any future mechanism are additional.

config.auth_strategy = :host_user
config.auth_options  = { resolve: ->(controller) { controller.current_user } }

The resolver returns the host's user object, or nil to deny. Whatever it returns is passed through Auth.normalize_actor, so config.authorize always receives a real object or nil -- never a bare true.

Instance Attribute Summary

Attributes inherited from Strategy

#options

Instance Method Summary collapse

Methods inherited from Strategy

#initialize

Constructor Details

This class inherits a constructor from AdminSuite::Auth::Strategy

Instance Method Details

#authenticate!(controller) ⇒ Object



19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
# File 'lib/admin_suite/auth/host_user.rb', line 19

def authenticate!(controller)
  resolver = options[:resolve]

  unless resolver.respond_to?(:call)
    Rails.logger&.error(
      "AdminSuite: auth_strategy :host_user requires config.auth_options[:resolve] " \
      "(a callable taking the controller). Denying every request until it is set."
    )
    return nil
  end

  actor =
    begin
      resolver.call(controller)
    rescue StandardError => e
      Rails.logger&.warn("AdminSuite: :host_user resolver raised #{e.class}: #{e.message}; denying.")
      nil
    end

  Auth.normalize_actor(actor)
end