Class: User
- Inherits:
-
ActiveRecord::Base
- Object
- ActiveRecord::Base
- User
- Defined in:
- app/models/user.rb
Instance Method Summary collapse
- #build_auth_header(token, client_id = 'default') ⇒ Object
-
#create_new_auth_token(client_id = nil) ⇒ Object
update user's auth token (should happen on each request).
- #extend_batch_buffer(token, client_id) ⇒ Object
- #valid_token?(token, client_id = 'default') ⇒ Boolean
Instance Method Details
#build_auth_header(token, client_id = 'default') ⇒ Object
73 74 75 76 77 78 79 80 |
# File 'app/models/user.rb', line 73 def build_auth_header(token, client_id='default') client_id ||= 'default' # client may use expiry to prevent validation request if expired expiry = self.tokens[client_id]['expiry'] return "token=#{token} client=#{client_id} expiry=#{expiry} uid=#{self.uid}" end |
#create_new_auth_token(client_id = nil) ⇒ Object
update user's auth token (should happen on each request)
49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 |
# File 'app/models/user.rb', line 49 def create_new_auth_token(client_id=nil) client_id ||= SecureRandom.urlsafe_base64(nil, false) last_token ||= nil token = SecureRandom.urlsafe_base64(nil, false) token_hash = BCrypt::Password.create(token) expiry = (Time.now.to_f + DeviseTokenAuth.token_lifespan).to_i * 1000 if self.tokens[client_id] and self.tokens[client_id]['token'] last_token = self.tokens[client_id]['token'] end self.tokens[client_id] = { token: token_hash, expiry: expiry, last_token: last_token, updated_at: Time.now } self.save! return build_auth_header(token, client_id) end |
#extend_batch_buffer(token, client_id) ⇒ Object
83 84 85 86 87 88 |
# File 'app/models/user.rb', line 83 def extend_batch_buffer(token, client_id) self.tokens[client_id]['updated_at'] = Time.now self.save! return build_auth_header(token, client_id) end |
#valid_token?(token, client_id = 'default') ⇒ Boolean
16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 |
# File 'app/models/user.rb', line 16 def valid_token?(token, client_id='default') client_id ||= 'default' return true if ( # ensure that expiry and token are set self.tokens[client_id]['expiry'] and self.tokens[client_id]['token'] and # ensure that the token was created within the last two weeks self.tokens[client_id]['expiry'] > DeviseTokenAuth.token_lifespan.ago.to_f * 1000 and # ensure that the token is valid BCrypt::Password.new(self.tokens[client_id]['token']) == token ) return true if ( # ensure that the last token and its creation time exist self.tokens[client_id]['updated_at'] and self.tokens[client_id]['last_token'] and # ensure that previous token falls within the batch buffer throttle time of the last request Time.parse(self.tokens[client_id]['updated_at']) > Time.now - DeviseTokenAuth.batch_request_buffer_throttle and # ensure that the token is valid BCrypt::Password.new(self.tokens[client_id]['last_token']) == token ) # return false if none of the above conditions are met return false end |