Module: DeviseTokenAuth::Concerns::User

Extended by:
ActiveSupport::Concern
Defined in:
app/models/devise_token_auth/concerns/user.rb

Instance Method Summary collapse

Instance Method Details

#build_auth_header(token, client_id = 'default') ⇒ Object



166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
# File 'app/models/devise_token_auth/concerns/user.rb', line 166

def build_auth_header(token, client_id='default')
  client_id ||= 'default'

  # client may use expiry to prevent validation request if expired
  # must be cast as string or headers will break
  expiry = self.tokens[client_id]['expiry'] || self.tokens[client_id][:expiry]

  return {
    "access-token" => token,
    "token-type"   => "Bearer",
    "client"       => client_id,
    "expiry"       => expiry.to_s,
    "uid"          => self.uid
  }
end

#build_auth_url(base_url, args) ⇒ Object



183
184
185
186
187
188
# File 'app/models/devise_token_auth/concerns/user.rb', line 183

def build_auth_url(base_url, args)
  args[:uid]    = self.uid
  args[:expiry] = self.tokens[args[:client_id]]['expiry']

  generate_url(base_url, args)
end

#confirmed? ⇒ Boolean



198
199
200
# File 'app/models/devise_token_auth/concerns/user.rb', line 198

def confirmed?
  self.devise_modules.exclude?(:confirmable) || super
end

#create_new_auth_token(client_id = nil) ⇒ Object

update user's auth token (should happen on each request)



142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
# File 'app/models/devise_token_auth/concerns/user.rb', line 142

def create_new_auth_token(client_id=nil)
  client_id  ||= SecureRandom.urlsafe_base64(nil, false)
  last_token ||= nil
  token        = SecureRandom.urlsafe_base64(nil, false)
  token_hash   = BCrypt::Password.create(token)
  expiry       = (Time.now + DeviseTokenAuth.token_lifespan).to_i

  if self.tokens[client_id] and self.tokens[client_id]['token']
    last_token = self.tokens[client_id]['token']
  end

  self.tokens[client_id] = {
    token:      token_hash,
    expiry:     expiry,
    last_token: last_token,
    updated_at: Time.now
  }

  self.save!

  return build_auth_header(token, client_id)
end

#extend_batch_buffer(token, client_id) ⇒ Object



191
192
193
194
195
196
# File 'app/models/devise_token_auth/concerns/user.rb', line 191

def extend_batch_buffer(token, client_id)
  self.tokens[client_id]['updated_at'] = Time.now
  self.save!

  return build_auth_header(token, client_id)
end

#send_confirmation_notification? ⇒ Boolean

this must be done from the controller so that additional params can be passed on from the client



98
99
100
# File 'app/models/devise_token_auth/concerns/user.rb', line 98

def send_confirmation_notification?
  false
end

#token_can_be_reused?(token, client_id) ⇒ Boolean

allow batch requests to use the previous token



122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
# File 'app/models/devise_token_auth/concerns/user.rb', line 122

def token_can_be_reused?(token, client_id)
  # ghetto HashWithIndifferentAccess
  updated_at = self.tokens[client_id]['updated_at'] || self.tokens[client_id][:updated_at]
  last_token = self.tokens[client_id]['last_token'] || self.tokens[client_id][:last_token]


  return true if (
    # ensure that the last token and its creation time exist
    updated_at and last_token and

    # ensure that previous token falls within the batch buffer throttle time of the last request
    Time.parse(updated_at) > Time.now - DeviseTokenAuth.batch_request_buffer_throttle and

    # ensure that the token is valid
    BCrypt::Password.new(last_token) == token
  )
end

#token_is_current?(token, client_id) ⇒ Boolean



103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
# File 'app/models/devise_token_auth/concerns/user.rb', line 103

def token_is_current?(token, client_id)
  # ghetto HashWithIndifferentAccess
  expiry     = self.tokens[client_id]['expiry'] || self.tokens[client_id][:expiry]
  token_hash = self.tokens[client_id]['token'] || self.tokens[client_id][:token]

  return true if (
    # ensure that expiry and token are set
    expiry and token and

    # ensure that the token has not yet expired
    DateTime.strptime(expiry.to_s, '%s') > Time.now and

    # ensure that the token is valid
    BCrypt::Password.new(token_hash) == token
  )
end

#token_validation_response ⇒ Object



202
203
204
205
206
# File 'app/models/devise_token_auth/concerns/user.rb', line 202

def token_validation_response
  self.as_json(except: [
    :tokens, :created_at, :updated_at
  ])
end

#valid_token?(token, client_id = 'default') ⇒ Boolean



83
84
85
86
87
88
89
90
91
92
93
# File 'app/models/devise_token_auth/concerns/user.rb', line 83

def valid_token?(token, client_id='default')
  client_id ||= 'default'

  return false unless self.tokens[client_id]

  return true if token_is_current?(token, client_id)
  return true if token_can_be_reused?(token, client_id)

  # return false if none of the above conditions are met
  return false
end