Class: Doorkeeper::Config
- Inherits:
-
Object
- Object
- Doorkeeper::Config
show all
- Extended by:
- Option
- Includes:
- Validations
- Defined in:
- lib/doorkeeper/config.rb,
lib/doorkeeper/config/option.rb,
lib/doorkeeper/config/validations.rb,
lib/doorkeeper/config/abstract_builder.rb
Overview
Doorkeeper option DSL could be reused in extensions to build their own
configurations. To use the Option DSL gems need to define builder_class method
that returns configuration Builder class. This exception raises when they don't
define it.
Defined Under Namespace
Modules: Option, Validations
Classes: AbstractBuilder, Builder
Instance Attribute Summary collapse
Instance Method Summary
collapse
Methods included from Option
extended, option
#validate!
Instance Attribute Details
#application_secret_fallback_strategy ⇒ Object
Returns the value of attribute application_secret_fallback_strategy.
459
460
461
|
# File 'lib/doorkeeper/config.rb', line 459
def application_secret_fallback_strategy
@application_secret_fallback_strategy
end
|
#enable_multiple_database_roles ⇒ Object
Returns the value of attribute enable_multiple_database_roles.
459
460
461
|
# File 'lib/doorkeeper/config.rb', line 459
def enable_multiple_database_roles
@enable_multiple_database_roles
end
|
#reuse_access_token ⇒ Object
Returns the value of attribute reuse_access_token.
459
460
461
|
# File 'lib/doorkeeper/config.rb', line 459
def reuse_access_token
@reuse_access_token
end
|
#token_secret_fallback_strategy ⇒ Object
Returns the value of attribute token_secret_fallback_strategy.
459
460
461
|
# File 'lib/doorkeeper/config.rb', line 459
def token_secret_fallback_strategy
@token_secret_fallback_strategy
end
|
Instance Method Details
#access_grant_model ⇒ ActiveRecord::Base, ...
Doorkeeper Access Grant model class.
486
487
488
|
# File 'lib/doorkeeper/config.rb', line 486
def access_grant_model
@access_grant_model ||= access_grant_class.constantize
end
|
#access_token_methods ⇒ Object
607
608
609
610
611
612
613
|
# File 'lib/doorkeeper/config.rb', line 607
def access_token_methods
@access_token_methods ||= %i[
from_bearer_authorization
from_access_token_param
from_bearer_param
]
end
|
#access_token_model ⇒ ActiveRecord::Base, ...
Doorkeeper Access Token model class.
478
479
480
|
# File 'lib/doorkeeper/config.rb', line 478
def access_token_model
@access_token_model ||= access_token_class.constantize
end
|
#allow_blank_redirect_uri?(application = nil) ⇒ Boolean
693
694
695
696
697
698
699
|
# File 'lib/doorkeeper/config.rb', line 693
def allow_blank_redirect_uri?(application = nil)
if allow_blank_redirect_uri.respond_to?(:call)
allow_blank_redirect_uri.call(grant_flows, application)
else
allow_blank_redirect_uri
end
end
|
#allow_grant_flow_for_client ⇒ Boolean
Allows to customize OAuth grant flows that each application support.
You can configure a custom block (or use a class respond to #call) that must
return true in case Application instance supports requested OAuth grant flow
during the authorization request to the server. This configuration doesn't
set flows per application, it only allows to check if application supports
specific grant flow.
For example you can add an additional database column to oauth_applications table,
say t.array :grant_flows, default: [], and store allowed grant flows that can
be used with this application there. Then when authorization requested Doorkeeper
will call this block to check if specific Application (passed with client_id and/or
client_secret) is allowed to perform the request for the specific grant type
(authorization, password, client_credentials, etc).
Example of the block:
->(flow, client) { client.grant_flows.include?(flow) }
In case this option invocation result is false, Doorkeeper server returns
:unauthorized_client error and stops the request.
329
|
# File 'lib/doorkeeper/config.rb', line 329
option :allow_grant_flow_for_client, default: ->(_grant_flow, _client) { true }
|
#allow_grant_flow_for_client?(grant_flow, client) ⇒ Boolean
701
702
703
704
705
|
# File 'lib/doorkeeper/config.rb', line 701
def allow_grant_flow_for_client?(grant_flow, client)
return true unless option_defined?(:allow_grant_flow_for_client)
allow_grant_flow_for_client.call(grant_flow, client)
end
|
#api_only ⇒ Object
498
499
500
|
# File 'lib/doorkeeper/config.rb', line 498
def api_only
@api_only ||= false
end
|
#application_model ⇒ ActiveRecord::Base, ...
Doorkeeper Application model class.
494
495
496
|
# File 'lib/doorkeeper/config.rb', line 494
def application_model
@application_model ||= application_class.constantize
end
|
#application_secret_hashed? ⇒ Boolean
569
570
571
|
# File 'lib/doorkeeper/config.rb', line 569
def application_secret_hashed?
instance_variable_defined?(:"@application_secret_strategy")
end
|
#application_secret_strategy ⇒ Object
577
578
579
|
# File 'lib/doorkeeper/config.rb', line 577
def application_secret_strategy
@application_secret_strategy ||= ::Doorkeeper::SecretStoring::Plain
end
|
#authorization_response_flows ⇒ Object
619
620
621
622
|
# File 'lib/doorkeeper/config.rb', line 619
def authorization_response_flows
@authorization_response_flows ||= enabled_grant_flows.select(&:handles_response_type?) +
deprecated_authorization_flows
end
|
#authorization_response_types ⇒ Object
628
629
630
|
# File 'lib/doorkeeper/config.rb', line 628
def authorization_response_types
authorization_response_flows.map(&:response_type_matches)
end
|
#calculate_authorization_response_types ⇒ Object
[NOTE]: deprecated and will be removed soon
664
665
666
|
# File 'lib/doorkeeper/config.rb', line 664
def calculate_authorization_response_types
[]
end
|
#calculate_grant_flows ⇒ Object
Calculates grant flows configured by the user in Doorkeeper
configuration considering registered aliases that is exposed
to single or multiple other flows.
679
680
681
682
683
684
685
686
687
688
689
690
691
|
# File 'lib/doorkeeper/config.rb', line 679
def calculate_grant_flows
configured_flows = grant_flows.map(&:to_s)
aliases = Doorkeeper::GrantFlow.aliases.keys.map(&:to_s)
flows = configured_flows - aliases
aliases.each do |flow_alias|
next unless configured_flows.include?(flow_alias)
flows.concat(Doorkeeper::GrantFlow.expand_alias(flow_alias))
end
flows.flatten.uniq
end
|
#calculate_token_grant_types ⇒ Object
[NOTE]: deprecated and will be removed soon
669
670
671
672
673
|
# File 'lib/doorkeeper/config.rb', line 669
def calculate_token_grant_types
types = grant_flows - ["implicit"]
types << "refresh_token" if refresh_token_enabled?
types
end
|
#clear_cache! ⇒ Object
464
465
466
467
468
469
470
471
472
|
# File 'lib/doorkeeper/config.rb', line 464
def clear_cache!
%i[
application_model
access_token_model
access_grant_model
].each do |var|
remove_instance_variable("@#{var}") if instance_variable_defined?("@#{var}")
end
end
|
#client_credentials_methods ⇒ Object
603
604
605
|
# File 'lib/doorkeeper/config.rb', line 603
def client_credentials_methods
@client_credentials_methods ||= %i[from_basic from_params]
end
|
#confirm_application_owner? ⇒ Boolean
557
558
559
|
# File 'lib/doorkeeper/config.rb', line 557
def confirm_application_owner?
option_set? :confirm_application_owner
end
|
#default_scopes ⇒ Object
581
582
583
|
# File 'lib/doorkeeper/config.rb', line 581
def default_scopes
@default_scopes ||= OAuth::Scopes.new
end
|
#deprecated_authorization_flows ⇒ Object
[NOTE]: deprecated and will be removed soon
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
|
# File 'lib/doorkeeper/config.rb', line 647
def deprecated_authorization_flows
response_types = calculate_authorization_response_types
if response_types.any?
::Kernel.warn <<~WARNING
Please, don't patch Doorkeeper::Config#calculate_authorization_response_types method.
Register your custom grant flows using the public API:
`Doorkeeper::GrantFlow.register(grant_flow_name, **options)`.
WARNING
end
response_types.map do |response_type|
Doorkeeper::GrantFlow::FallbackFlow.new(response_type, response_type_matches: response_type)
end
end
|
#deprecated_token_grant_types_resolver ⇒ Object
[NOTE]: deprecated and will be removed soon
637
638
639
|
# File 'lib/doorkeeper/config.rb', line 637
def deprecated_token_grant_types_resolver
@deprecated_token_grant_types ||= calculate_token_grant_types
end
|
#dynamic_scopes_delimiter ⇒ Object
549
550
551
|
# File 'lib/doorkeeper/config.rb', line 549
def dynamic_scopes_delimiter
@dynamic_scopes_delimiter
end
|
#enable_application_owner? ⇒ Boolean
541
542
543
|
# File 'lib/doorkeeper/config.rb', line 541
def enable_application_owner?
option_set? :enable_application_owner
end
|
#enable_dynamic_scopes? ⇒ Boolean
545
546
547
|
# File 'lib/doorkeeper/config.rb', line 545
def enable_dynamic_scopes?
option_set? :enable_dynamic_scopes
end
|
#enabled_grant_flows ⇒ Object
615
616
617
|
# File 'lib/doorkeeper/config.rb', line 615
def enabled_grant_flows
@enabled_grant_flows ||= calculate_grant_flows.map { |name| Doorkeeper::GrantFlow.get(name) }.compact
end
|
537
538
539
|
# File 'lib/doorkeeper/config.rb', line 537
def enforce_configured_scopes?
option_set? :enforce_configured_scopes
end
|
#enforce_content_type ⇒ Object
502
503
504
|
# File 'lib/doorkeeper/config.rb', line 502
def enforce_content_type
@enforce_content_type ||= false
end
|
#force_pkce? ⇒ Boolean
533
534
535
|
# File 'lib/doorkeeper/config.rb', line 533
def force_pkce?
option_set? :force_pkce
end
|
#native_authorization_code_route ⇒ Object
641
642
643
644
|
# File 'lib/doorkeeper/config.rb', line 641
def native_authorization_code_route
@use_url_path_for_native_authorization = false unless defined?(@use_url_path_for_native_authorization)
@use_url_path_for_native_authorization ? "/:code" : "/native"
end
|
#option_defined?(name) ⇒ Boolean
707
708
709
|
# File 'lib/doorkeeper/config.rb', line 707
def option_defined?(name)
instance_variable_defined?("@#{name}")
end
|
#optional_scopes ⇒ Object
585
586
587
|
# File 'lib/doorkeeper/config.rb', line 585
def optional_scopes
@optional_scopes ||= OAuth::Scopes.new
end
|
#pkce_code_challenge_methods_supported ⇒ Object
597
598
599
600
601
|
# File 'lib/doorkeeper/config.rb', line 597
def pkce_code_challenge_methods_supported
return [] unless access_grant_model.pkce_supported?
pkce_code_challenge_methods
end
|
#polymorphic_resource_owner? ⇒ Boolean
553
554
555
|
# File 'lib/doorkeeper/config.rb', line 553
def polymorphic_resource_owner?
option_set? :polymorphic_resource_owner
end
|
#raise_on_errors? ⇒ Boolean
561
562
563
|
# File 'lib/doorkeeper/config.rb', line 561
def raise_on_errors?
handle_auth_errors == :raise
end
|
#redirect_on_errors? ⇒ Boolean
565
566
567
|
# File 'lib/doorkeeper/config.rb', line 565
def redirect_on_errors?
handle_auth_errors == :redirect
end
|
#refresh_token_enabled? ⇒ Boolean
506
507
508
509
510
511
512
|
# File 'lib/doorkeeper/config.rb', line 506
def refresh_token_enabled?
if defined?(@refresh_token_enabled)
@refresh_token_enabled
else
false
end
end
|
#resolve_controller(name) ⇒ Object
514
515
516
517
518
519
520
521
522
523
|
# File 'lib/doorkeeper/config.rb', line 514
def resolve_controller(name)
config_option = public_send(:"#{name}_controller")
controller_name = if config_option.respond_to?(:call)
instance_exec(&config_option)
else
config_option
end
controller_name.constantize
end
|
#revoke_previous_authorization_code_token? ⇒ Boolean
529
530
531
|
# File 'lib/doorkeeper/config.rb', line 529
def revoke_previous_authorization_code_token?
option_set? :revoke_previous_authorization_code_token
end
|
#revoke_previous_client_credentials_token? ⇒ Boolean
525
526
527
|
# File 'lib/doorkeeper/config.rb', line 525
def revoke_previous_client_credentials_token?
option_set? :revoke_previous_client_credentials_token
end
|
#scopes ⇒ Object
589
590
591
|
# File 'lib/doorkeeper/config.rb', line 589
def scopes
@scopes ||= default_scopes + optional_scopes
end
|
#scopes_by_grant_type ⇒ Object
593
594
595
|
# File 'lib/doorkeeper/config.rb', line 593
def scopes_by_grant_type
@scopes_by_grant_type ||= {}
end
|
#token_grant_flows ⇒ Object
624
625
626
|
# File 'lib/doorkeeper/config.rb', line 624
def token_grant_flows
@token_grant_flows ||= calculate_token_grant_flows
end
|
#token_grant_types ⇒ Object
632
633
634
|
# File 'lib/doorkeeper/config.rb', line 632
def token_grant_types
token_grant_flows.map(&:grant_type_matches)
end
|
#token_secret_strategy ⇒ Object
573
574
575
|
# File 'lib/doorkeeper/config.rb', line 573
def token_secret_strategy
@token_secret_strategy ||= ::Doorkeeper::SecretStoring::Plain
end
|