Class: CloudKit::OpenIDFilter

Inherits:
Object
  • Object
show all
Includes:
Util
Defined in:
lib/cloudkit/openid_filter.rb

Overview

An OpenIDFilter provides OpenID authentication, listening for upstream OAuth authentication and bypassing if already authorized.

Responds to the following URIs:

/login
/logout
/openid_complete

Constant Summary collapse

@@lock =
Mutex.new
@@store =
nil

Instance Method Summary collapse

Methods included from Util

#erb, #r, #unquote

Constructor Details

#initialize(app, options = {}) ⇒ OpenIDFilter

Returns a new instance of OpenIDFilter.



17
18
19
# File 'lib/cloudkit/openid_filter.rb', line 17

def initialize(app, options={})
  @app = app; @options = options
end

Instance Method Details

#base_url(request) ⇒ Object



148
149
150
# File 'lib/cloudkit/openid_filter.rb', line 148

def base_url(request)
  "#{request.scheme}://#{request.env['HTTP_HOST']}/"
end

#begin_openid_login(request) ⇒ Object



80
81
82
83
84
85
86
87
88
89
90
# File 'lib/cloudkit/openid_filter.rb', line 80

def (request)
  begin
    response = openid_consumer(request).begin(request[:openid_url])
  rescue => e
    request.flash[:error] = e
    return (request)
  end

  redirect_url = response.redirect_url(base_url(request), full_url(request))
  Rack::Response.new([], 302, {'Location' => redirect_url}).finish
end

#call(env) ⇒ Object



21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
# File 'lib/cloudkit/openid_filter.rb', line 21

def call(env)
  @@lock.synchronize do
    @@store = OpenIDStore.new(env[CLOUDKIT_STORAGE_URI])
    @users  = UserStore.new(env[CLOUDKIT_STORAGE_URI])
    @@store.get_association('x') rescue nil # refresh sqlite3
  end unless @@store

  request = Request.new(env)
  request.announce_auth(CLOUDKIT_OPENID_FILTER_KEY)

  case request
  when r(:get, request.); (request)
  when r(:post, request.); (request)
  when r(:get, '/openid_complete'); (request)
  when r(:post, request.logout_url); logout(request)
  else
    if (root_request?(request) || valid_auth_key?(request) || logged_in?(request))
      @app.call(env)
    else
      if request.env[CLOUDKIT_AUTH_CHALLENGE]
        store_location(request)
        erb(
          request,
          :openid_login,
          request.env[CLOUDKIT_AUTH_CHALLENGE].merge('Content-Type' => 'text/html'),
          401)
      elsif !request.via.include?(CLOUDKIT_OAUTH_FILTER_KEY)
        store_location(request)
        (request)
      else
        Rack::Response.new('server misconfigured', 500).finish
      end
    end
  end
end

#complete_openid_login(request) ⇒ Object



92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
# File 'lib/cloudkit/openid_filter.rb', line 92

def (request)
  begin
    idp_response = openid_consumer(request).complete(request.params, full_url(request))
  rescue => e
    request.flash[:error] = e
    return (request)
  end

  if idp_response.is_a?(OpenID::Consumer::FailureResponse)
    request.flash[:error] = idp_response.message
    return (request)
  end

  result = @users.get(
    '/cloudkit_login_view',
    :identity_url => idp_response.endpoint.claimed_id)
  user_uris = result.parsed_content['uris']

  if user_uris.empty?
    json     = JSON.generate(:identity_url => idp_response.endpoint.claimed_id)
    result   = @users.post('/cloudkit_users', :json => json)
    user_uri = result.parsed_content['uri']
  else
    user_uri = user_uris.first
  end
  user_result = @users.resolve_uris([user_uri]).first
  user        = user_result.parsed_content

  if request.session['user_uri'] = user_uri
    request.current_user = user_uri
    user['remember_me_expiration'] = two_weeks_from_now
    user['remember_me_token'] = Base64.encode64(
      OpenSSL::Random.random_bytes(32)).gsub(/\W/,'')
    url      = request.session.delete('return_to')
    response = Rack::Response.new(
      [],
      302,
      {'Location' => (url || '/'), 'Content-Type' => 'text/html'})
    response.set_cookie(
      'remember_me', {
        :value   => user['remember_me_token'],
        :expires => Time.at(user['remember_me_expiration']).utc})
    json = JSON.generate(user)
    @users.put(user_uri, :etag => user_result.etag, :json => json)
    request.flash[:notice] = 'You have been logged in.'
    response.finish
  else
    request.flash[:error] = 'Could not log on with your OpenID.'
    (request)
  end
end

#full_url(request) ⇒ Object



152
153
154
# File 'lib/cloudkit/openid_filter.rb', line 152

def full_url(request)
  base_url(request) + 'openid_complete'
end

#logged_in?(request) ⇒ Boolean

Returns:

  • (Boolean)


156
157
158
159
160
# File 'lib/cloudkit/openid_filter.rb', line 156

def logged_in?(request)
  logged_in = user_in_session?(request) || valid_remember_me_token?(request)
  request.current_user = request.session['user_uri'] if logged_in
  logged_in
end

#login_redirect(request) ⇒ Object



144
145
146
# File 'lib/cloudkit/openid_filter.rb', line 144

def (request)
  Rack::Response.new([], 302, {'Location' => request.}).finish
end

#logout(request) ⇒ Object



57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
# File 'lib/cloudkit/openid_filter.rb', line 57

def logout(request)
  user_uri = request.session.delete('user_uri')
  result   = @users.get(user_uri)
  user     = result.parsed_content
  user.delete('remember_me_token')
  user.delete('remember_me_expiration')
  json = JSON.generate(user)
  @users.put(user_uri, :etag => result.etag, :json => json)

  request.env[CLOUDKIT_AUTH_KEY] = nil
  request.flash['info'] = 'You have been logged out.'
  response = Rack::Response.new(
    [],
    302,
    {'Location' => request., 'Content-Type' => 'text/html'})
  response.delete_cookie('remember_me')
  response.finish
end

#openid_consumer(request) ⇒ Object



178
179
180
181
# File 'lib/cloudkit/openid_filter.rb', line 178

def openid_consumer(request)
  @openid_consumer ||= OpenID::Consumer.new(
    request.session, OpenIDStore.new)
end

#request_login(request) ⇒ Object



76
77
78
# File 'lib/cloudkit/openid_filter.rb', line 76

def (request)
  erb(request, :openid_login)
end

#root_request?(request) ⇒ Boolean

Returns:

  • (Boolean)


170
171
172
# File 'lib/cloudkit/openid_filter.rb', line 170

def root_request?(request)
  request.path_info == '/' || request.path_info == '/favicon.ico'
end

#store_location(request) ⇒ Object



166
167
168
# File 'lib/cloudkit/openid_filter.rb', line 166

def store_location(request)
  request.session['return_to'] = request.url
end

#two_weeks_from_nowObject



204
205
206
# File 'lib/cloudkit/openid_filter.rb', line 204

def two_weeks_from_now
  Time.now.to_i+1209600
end

#user_in_session?(request) ⇒ Boolean

Returns:

  • (Boolean)


162
163
164
# File 'lib/cloudkit/openid_filter.rb', line 162

def user_in_session?(request)
  request.session['user_uri'] != nil
end

#valid_auth_key?(request) ⇒ Boolean

Returns:

  • (Boolean)


174
175
176
# File 'lib/cloudkit/openid_filter.rb', line 174

def valid_auth_key?(request)
  request.env[CLOUDKIT_AUTH_KEY] && request.env[CLOUDKIT_AUTH_KEY] != ''
end

#valid_remember_me_token?(request) ⇒ Boolean

Returns:

  • (Boolean)


183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
# File 'lib/cloudkit/openid_filter.rb', line 183

def valid_remember_me_token?(request)
  return false unless token = request.cookies['remember_me']

  result = @users.get('/cloudkit_login_view', :remember_me_token => token)
  return false unless result.status == 200

  user_uris = result.parsed_content['uris']
  return false unless user_uris.try(:size) == 1

  user_uri    = user_uris.first
  user_result = @users.resolve_uris([user_uri]).first
  user        = user_result.parsed_content
  return false unless Time.now.to_i < user['remember_me_expiration']

  user['remember_me_expiration'] = two_weeks_from_now
  json = JSON.generate(user)
  @users.put(user_uri, :etag => user_result.etag, :json => json)
  request.session['user_uri'] = user_uri
  true
end