Class: RestClient::Resource

Inherits:
Object
  • Object
show all
Includes:
Conjur::Cast, Conjur::Escape, Conjur::LogSource
Defined in:
lib/conjur/api.rb

Instance Method Summary collapse

Methods included from Conjur::LogSource

#log

Methods included from Conjur::Escape

#fully_escape, #path_escape, #query_escape

Constructor Details

#initialize(url, options = nil, &block) ⇒ Resource

Returns a new instance of Resource.



53
54
55
# File 'lib/conjur/api.rb', line 53

def initialize url, options = nil, &block
  initialize_without_defaults url, default_options.merge(options || {}), &block
end

Instance Method Details

#conjur_apiConjur::API

Creates a Conjur API from this resource's authorization header.

The new API is created using the token, so it will not be able to refresh when the token expires (after about 8 minutes). This is equivalent to creating an Conjur::API instance with Conjur::API.new_from_token.

Returns:



87
88
89
90
91
92
93
94
# File 'lib/conjur/api.rb', line 87

def conjur_api
  api = Conjur::API.new_from_token token, remote_ip
  if conjur_privilege
    api.with_privilege conjur_privilege
  else
    api
  end
end

#conjur_privilegeObject



117
118
119
# File 'lib/conjur/api.rb', line 117

def conjur_privilege
  options[:headers][:x_conjur_privilege]
end

#default_optionsObject



57
58
59
60
61
# File 'lib/conjur/api.rb', line 57

def default_options
  {
    ssl_cert_store: OpenSSL::SSL::SSLContext::DEFAULT_CERT_STORE
  }
end

#initialize_without_defaultsObject



51
# File 'lib/conjur/api.rb', line 51

alias_method :initialize_without_defaults, :initialize

#remote_ipObject



113
114
115
# File 'lib/conjur/api.rb', line 113

def remote_ip
  options[:headers][:x_forwarded_for]
end

#tokenHash

Get an authentication token from the clients Authorization header.

Useful fields in the token include "data", which holds the username for which the token was issued, and "timestamp", which contains the time at which the token was issued. The token will expire 8 minutes after timestamp, but we recommend you treat the lifespan as about 5 minutes to account for time differences.

Returns:

  • (Hash)

    the parsed authentication token



104
105
106
107
108
109
110
111
# File 'lib/conjur/api.rb', line 104

def token
  authorization = options[:headers][:authorization]
  if authorization && authorization.to_s[/^Token token="(.*)"/]
    JSON.parse(Base64.decode64($1))
  else
    raise AuthorizationError.new("Authorization missing")
  end
end

#usernameString

The username this resource authenticates as.

Returns:

  • (String)

    the username



124
125
126
# File 'lib/conjur/api.rb', line 124

def username
  options[:user] || options[:username]
end