Class: Drillbit::Tokens::JsonWebToken

Inherits:
Object
  • Object
show all
Defined in:
lib/drillbit/tokens/json_web_token.rb

Constant Summary collapse

TRANSFORMATION_EXCEPTIONS =
[
  JSON::JWT::Exception,
  JSON::JWT::InvalidFormat,
  JSON::JWT::VerificationFailed,
  JSON::JWT::UnexpectedAlgorithm,
  JWT::DecodeError,
  JWT::VerificationError,
  JWT::ExpiredSignature,
  JWT::IncorrectAlgorithm,
  JWT::ImmatureSignature,
  JWT::InvalidIssuerError,
  JWT::InvalidIatError,
  JWT::InvalidAudError,
  JWT::InvalidSubError,
  JWT::InvalidJtiError,
  OpenSSL::PKey::RSAError,
  OpenSSL::Cipher::CipherError,
].freeze

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(data:, headers: {}, private_key: Drillbit.configuration.token_private_key) ⇒ JsonWebToken

Returns a new instance of JsonWebToken.



35
36
37
38
39
40
41
42
# File 'lib/drillbit/tokens/json_web_token.rb', line 35

def initialize(data:,
               headers:     {},
               private_key: Drillbit.configuration.token_private_key)

  self.data        = data
  self.headers     = headers
  self.private_key = private_key
end

Instance Attribute Details

#dataObject

Returns the value of attribute data.



31
32
33
# File 'lib/drillbit/tokens/json_web_token.rb', line 31

def data
  @data
end

#headersObject

Returns the value of attribute headers.



31
32
33
# File 'lib/drillbit/tokens/json_web_token.rb', line 31

def headers
  @headers
end

#private_keyObject

Returns the value of attribute private_key.



31
32
33
# File 'lib/drillbit/tokens/json_web_token.rb', line 31

def private_key
  @private_key
end

Class Method Details

.build(id: SecureRandom.uuid, audience: Drillbit.configuration.default_token_audience, expiration: Time.now.utc.to_i + (60 * Drillbit.configuration.default_token_expiration_in_minutes), issuer: Drillbit.configuration.default_token_issuer || 'Drillbit', issued_at: Time.now.utc, not_before: Time.now.utc, owner: nil, roles: Drillbit.configuration.default_token_roles, subject: Drillbit.configuration.default_token_subject, subject_id:, token_private_key: Drillbit.configuration.token_private_key) ⇒ Object

rubocop:disable Metrics/ParameterLists, Metrics/AbcSize, Metrics/LineLength :reek:DuplicateMethodCall



54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
# File 'lib/drillbit/tokens/json_web_token.rb', line 54

def self.build(id:                SecureRandom.uuid,
               audience:          Drillbit.configuration.default_token_audience,
               expiration:        Time.now.utc.to_i + (60 * Drillbit.configuration.default_token_expiration_in_minutes),
               issuer:            Drillbit.configuration.default_token_issuer || 'Drillbit',
               issued_at:         Time.now.utc,
               not_before:        Time.now.utc,
               owner:             nil,
               roles:             Drillbit.configuration.default_token_roles,
               subject:           Drillbit.configuration.default_token_subject,
               subject_id:,
               token_private_key: Drillbit.configuration.token_private_key)

  owner ||= subject_id

  new(
    private_key: token_private_key,
    data:        {
      'aud' => audience,
      'exp' => expiration.to_i,
      'iat' => issued_at.to_i,
      'iss' => issuer,
      'jti' => id,
      'nbf' => not_before.to_i,
      'own' => owner,
      'rol' => roles.join(','),
      'sid' => subject_id,
      'sub' => subject,
    },
  )
end

.build_from_request(request_token) ⇒ Object



44
45
46
47
48
49
50
# File 'lib/drillbit/tokens/json_web_token.rb', line 44

def self.build_from_request(request_token)
  return Tokens::JsonWebTokens::Null.instance unless request_token

  data, headers = *request_token

  new(data: data, headers: headers)
end

.from_jwe(encrypted_token, private_key: Drillbit.configuration.token_private_key) ⇒ Object



176
177
178
179
180
181
182
183
184
185
186
187
188
# File 'lib/drillbit/tokens/json_web_token.rb', line 176

def self.from_jwe(encrypted_token,
                  private_key: Drillbit.configuration.token_private_key)

  return JsonWebTokens::Null.instance if encrypted_token.to_s == ''

  decrypted_token = JSON::JWT.
                      decode(encrypted_token, private_key).
                      plain_text

  from_jws(decrypted_token, private_key: private_key)
rescue *TRANSFORMATION_EXCEPTIONS
  JsonWebTokens::Invalid.instance
end

.from_jws(signed_token, private_key: Drillbit.configuration.token_private_key) ⇒ Object



190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
# File 'lib/drillbit/tokens/json_web_token.rb', line 190

def self.from_jws(signed_token,
                  private_key: Drillbit.configuration.token_private_key)

  return JsonWebTokens::Null.instance if signed_token.to_s == ''

  decoded = JWT.decode(
                        signed_token,
                        private_key,
                        true,
                        algorithm:         'RS256',
                        verify_expiration: true,
                        verify_not_before: true,
                        verify_iat:        true,
                        leeway:            5,
  )

  data, headers = *decoded

  new(data:        data,
      headers:     headers,
      private_key: private_key)
rescue *TRANSFORMATION_EXCEPTIONS
  JsonWebTokens::Invalid.instance
end

Instance Method Details

#audienceObject



106
107
108
# File 'lib/drillbit/tokens/json_web_token.rb', line 106

def audience
  data['aud']
end

#blank?Boolean

Returns:

  • (Boolean)


90
91
92
# File 'lib/drillbit/tokens/json_web_token.rb', line 90

def blank?
  data.empty?
end

#empty?Boolean

Returns:

  • (Boolean)


98
99
100
# File 'lib/drillbit/tokens/json_web_token.rb', line 98

def empty?
  data.empty?
end

#expirationObject



118
119
120
# File 'lib/drillbit/tokens/json_web_token.rb', line 118

def expiration
  data['exp']
end

#idObject



122
123
124
# File 'lib/drillbit/tokens/json_web_token.rb', line 122

def id
  data['jti']
end

#issued_atObject



110
111
112
# File 'lib/drillbit/tokens/json_web_token.rb', line 110

def issued_at
  data['iat']
end

#issuerObject



114
115
116
# File 'lib/drillbit/tokens/json_web_token.rb', line 114

def issuer
  data['iss']
end

#not_beforeObject



126
127
128
# File 'lib/drillbit/tokens/json_web_token.rb', line 126

def not_before
  data['nbf']
end

#owner_idObject



130
131
132
# File 'lib/drillbit/tokens/json_web_token.rb', line 130

def owner_id
  data['own']
end

#present?Boolean

Returns:

  • (Boolean)


94
95
96
# File 'lib/drillbit/tokens/json_web_token.rb', line 94

def present?
  data.any?
end

#rolesObject



148
149
150
# File 'lib/drillbit/tokens/json_web_token.rb', line 148

def roles
  @roles ||= data['rol'].split(',')
end

#subjectObject



138
139
140
# File 'lib/drillbit/tokens/json_web_token.rb', line 138

def subject
  data['sub']
end

#subject_idObject



134
135
136
# File 'lib/drillbit/tokens/json_web_token.rb', line 134

def subject_id
  data['sid']
end

#to_hObject



102
103
104
# File 'lib/drillbit/tokens/json_web_token.rb', line 102

def to_h
  [data, headers]
end

#to_jweObject



168
169
170
# File 'lib/drillbit/tokens/json_web_token.rb', line 168

def to_jwe
  @jwe ||= to_jws.encrypt(private_key, 'RSA-OAEP', 'A256GCM')
end

#to_jwe_sObject



172
173
174
# File 'lib/drillbit/tokens/json_web_token.rb', line 172

def to_jwe_s
  @jwe_s ||= to_jwe.to_s
end

#to_jwsObject



160
161
162
# File 'lib/drillbit/tokens/json_web_token.rb', line 160

def to_jws
  @jws ||= to_jwt.sign(private_key,    'RS256')
end

#to_jws_sObject



164
165
166
# File 'lib/drillbit/tokens/json_web_token.rb', line 164

def to_jws_s
  @jws_s ||= to_jws.to_s
end

#to_jwtObject



152
153
154
# File 'lib/drillbit/tokens/json_web_token.rb', line 152

def to_jwt
  @jwt ||= JSON::JWT.new(data)
end

#to_jwt_sObject



156
157
158
# File 'lib/drillbit/tokens/json_web_token.rb', line 156

def to_jwt_s
  @jwt_s ||= to_jwt.to_s
end

#valid?Boolean

rubocop:enable Metrics/ParameterLists, Metrics/AbcSize, Metrics/LineLength

Returns:

  • (Boolean)


86
87
88
# File 'lib/drillbit/tokens/json_web_token.rb', line 86

def valid?
  true
end