Class: Clerk::Proxy

Inherits:
Object
  • Object
show all
Defined in:
lib/clerk/proxy.rb

Constant Summary collapse

CACHE_TTL =

seconds

60

Instance Method Summary collapse

Constructor Details

#initialize(session_claims: nil, session_token: nil) ⇒ Proxy

Returns a new instance of Proxy.



11
12
13
14
# File 'lib/clerk/proxy.rb', line 11

def initialize(session_claims: nil, session_token: nil)
  @session_claims = session_claims
  @session_token = session_token
end

Instance Method Details

#organizationObject



40
41
42
43
44
# File 'lib/clerk/proxy.rb', line 40

def organization
  return nil unless organization?

  @organization ||= fetch_org(organization_id)
end

#organization?Boolean

Returns:

  • (Boolean)


36
37
38
# File 'lib/clerk/proxy.rb', line 36

def organization?
  !organization_id.nil?
end

#organization_idObject



46
47
48
49
50
# File 'lib/clerk/proxy.rb', line 46

def organization_id
  return nil unless user?

  @session_claims['org_id']
end

#organization_permissionsObject



58
59
60
61
62
# File 'lib/clerk/proxy.rb', line 58

def organization_permissions
  return nil if @session_claims.nil?

  @session_claims['org_permissions']
end

#organization_roleObject



52
53
54
55
56
# File 'lib/clerk/proxy.rb', line 52

def organization_role
  return nil if @session_claims.nil?

  @session_claims['org_role']
end

#sessionObject



16
17
18
# File 'lib/clerk/proxy.rb', line 16

def session
  @session_claims
end

#sign_in_urlObject



111
112
113
# File 'lib/clerk/proxy.rb', line 111

def 
  ENV['CLERK_SIGN_IN_URL']
end

#sign_out_urlObject



115
116
117
# File 'lib/clerk/proxy.rb', line 115

def sign_out_url
  ENV['CLERK_SIGN_OUT_URL']
end

#sign_up_urlObject



119
120
121
# File 'lib/clerk/proxy.rb', line 119

def 
  ENV['CLERK_SIGN_UP_URL']
end

#userObject



24
25
26
27
28
# File 'lib/clerk/proxy.rb', line 24

def user
  return nil unless user?

  @user ||= fetch_user(user_id)
end

#user?Boolean

Returns:

  • (Boolean)


20
21
22
# File 'lib/clerk/proxy.rb', line 20

def user?
  !@session_claims.nil?
end

#user_idObject



30
31
32
33
34
# File 'lib/clerk/proxy.rb', line 30

def user_id
  return nil unless user?

  @session_claims['sub']
end

#user_needs_reverification?(preset = StepUp::Preset::STRICT) ⇒ Boolean

Returns:

  • (Boolean)


92
93
94
# File 'lib/clerk/proxy.rb', line 92

def user_needs_reverification?(preset = StepUp::Preset::STRICT)
  !user_reverified?(preset)
end

#user_require_reverification!(preset = StepUp::Preset::STRICT) {|preset| ... } ⇒ Object

Yields:

  • (preset)


96
97
98
99
# File 'lib/clerk/proxy.rb', line 96

def user_require_reverification!(preset = StepUp::Preset::STRICT, &block)
  return unless user_needs_reverification?(preset)
  yield(preset) if block_given?
end

#user_reverification_rack_response(config = nil) ⇒ Object

Raises:

  • (ArgumentError)


101
102
103
104
105
106
107
108
109
# File 'lib/clerk/proxy.rb', line 101

def user_reverification_rack_response(config = nil)
  raise ArgumentError, 'Missing config, please pass a preset a la `Clerk::StepUp::Preset::*`' if config.nil?

  [
    403,
    {Clerk::CONTENT_TYPE_HEADER => 'application/json'},
    [StepUp::Reverification.error_payload(config).to_json]
  ]
end

#user_reverified?(params) ⇒ Boolean

Returns true if the session needs to perform step up verification

Returns:

  • (Boolean)


65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
# File 'lib/clerk/proxy.rb', line 65

def user_reverified?(params)
  return false unless user?

  fva = session_claims['fva']

  # the feature is disabled
  return true if fva.nil?

  level = params[:level]
  after_minutes = params[:after_minutes].to_i

  return false if after_minutes.nil? || level.nil?

  factor1_age, factor2_age = fva
  is_valid_factor1 = factor1_age != -1 && after_minutes > factor1_age
  is_valid_factor2 = factor2_age != -1 && after_minutes > factor2_age

  case level
  when :first_factor
    is_valid_factor1
  when :second_factor
    factor2_age == -1 ? is_valid_factor1 : is_valid_factor2
  when :multi_factor
    factor2_age == -1 ? is_valid_factor1 : is_valid_factor1 && is_valid_factor2
  end
end