Module: AdminSuite::Mcp::Authorization
- Defined in:
- lib/admin_suite/mcp/authorization.rb
Constant Summary collapse
- DENIED_MESSAGE =
"Not authorized, or no such resource."
Class Method Summary collapse
- .authorize_record?(config:, actor:, record:, request: nil) ⇒ Boolean
- .authorize_resource!(name:, actor:, action:, request: nil) ⇒ Object
- .denied_response ⇒ Object
- .error_response(message) ⇒ Object
- .readable_resources(actor:, request: nil) ⇒ Object
Class Method Details
.authorize_record?(config:, actor:, record:, request: nil) ⇒ Boolean
26 27 28 29 30 |
# File 'lib/admin_suite/mcp/authorization.rb', line 26 def (config:, actor:, record:, request: nil) return false if AdminSuite.config..nil? || Auth.normalize_actor(actor).nil? permitted?(config: config, actor: actor, record: record, action: :read, request: request) end |
.authorize_resource!(name:, actor:, action:, request: nil) ⇒ Object
17 18 19 20 21 22 23 24 |
# File 'lib/admin_suite/mcp/authorization.rb', line 17 def (name:, actor:, action:, request: nil) return nil if AdminSuite.config..nil? || Auth.normalize_actor(actor).nil? config = resource_configs.find { |resource| resource.resource_name == name.to_s } return nil unless config && mcp_enabled?(config) config if permitted?(config: config, actor: actor, action: action, request: request) end |
.denied_response ⇒ Object
32 33 34 |
# File 'lib/admin_suite/mcp/authorization.rb', line 32 def denied_response ::MCP::Tool::Response.new([{ type: "text", text: DENIED_MESSAGE }], error: true) end |
.error_response(message) ⇒ Object
36 37 38 |
# File 'lib/admin_suite/mcp/authorization.rb', line 36 def error_response() ::MCP::Tool::Response.new([{ type: "text", text: }], error: true) end |
.readable_resources(actor:, request: nil) ⇒ Object
9 10 11 12 13 14 15 |
# File 'lib/admin_suite/mcp/authorization.rb', line 9 def readable_resources(actor:, request: nil) return [] if AdminSuite.config..nil? || Auth.normalize_actor(actor).nil? resource_configs.select do |config| mcp_enabled?(config) && permitted?(config: config, actor: actor, action: :read, request: request) end end |