Class: Grape::Middleware::Auth::OAuth2

Inherits:
Base
  • Object
show all
Defined in:
lib/grape/middleware/auth/oauth2.rb

Overview

OAuth 2.0 authorization for Grape APIs.

Instance Attribute Summary

Attributes inherited from Base

#app, #env, #options

Instance Method Summary collapse

Methods inherited from Base

#after, #call, #call!, #content_type, #content_type_for, #content_types, #initialize, #mime_types, #request, #response

Constructor Details

This class inherits a constructor from Grape::Middleware::Base

Instance Method Details

#authorization_headerObject


33
34
35
36
37
38
# File 'lib/grape/middleware/auth/oauth2.rb', line 33

def authorization_header
  options[:accepted_headers].each do |head|
    return env[head] if env[head]
  end
  nil
end

#beforeObject


14
15
16
# File 'lib/grape/middleware/auth/oauth2.rb', line 14

def before
  verify_token(token_parameter || token_header)
end

#default_optionsObject


4
5
6
7
8
9
10
11
12
# File 'lib/grape/middleware/auth/oauth2.rb', line 4

def default_options
  {
    token_class: 'AccessToken',
    realm: 'OAuth API',
    parameter: %w(bearer_token oauth_token),
    accepted_headers: %w(HTTP_AUTHORIZATION X_HTTP_AUTHORIZATION X-HTTP_AUTHORIZATION REDIRECT_X_HTTP_AUTHORIZATION),
    header: [/Bearer (.*)/i, /OAuth (.*)/i]
  }
end

#error_out(status, error) ⇒ Object


61
62
63
64
65
66
67
68
# File 'lib/grape/middleware/auth/oauth2.rb', line 61

def error_out(status, error)
  throw :error,
        message: error,
        status: status,
        headers: {
          'WWW-Authenticate' => "OAuth realm='#{options[:realm]}', error='#{error}'"
        }
end

#token_classObject


40
41
42
# File 'lib/grape/middleware/auth/oauth2.rb', line 40

def token_class
  @klass ||= eval(options[:token_class]) # rubocop:disable Eval
end

#token_headerObject


25
26
27
28
29
30
31
# File 'lib/grape/middleware/auth/oauth2.rb', line 25

def token_header
  return false unless authorization_header
  Array(options[:header]).each do |regexp|
    return $1 if authorization_header =~ regexp
  end
  nil
end

#token_parameterObject


18
19
20
21
22
23
# File 'lib/grape/middleware/auth/oauth2.rb', line 18

def token_parameter
  Array(options[:parameter]).each do |p|
    return request[p] if request[p]
  end
  nil
end

#verify_token(token) ⇒ Object


44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
# File 'lib/grape/middleware/auth/oauth2.rb', line 44

def verify_token(token)
  token = token_class.verify(token)
  if token
    if token.respond_to?(:expired?) && token.expired?
      error_out(401, 'expired_token')
    else
      if !token.respond_to?(:permission_for?) || token.permission_for?(env)
        env['api.token'] = token
      else
        error_out(403, 'insufficient_scope')
      end
    end
  else
    error_out(401, 'invalid_token')
  end
end