Class: JSONAPI::Authorization::AuthorizingProcessor
- Inherits:
-
Processor
- Object
- Processor
- JSONAPI::Authorization::AuthorizingProcessor
- Defined in:
- lib/jsonapi/authorization/authorizing_processor.rb
Instance Method Summary collapse
- #authorize_create_resource ⇒ Object
- #authorize_create_to_many_relationship ⇒ Object
- #authorize_find ⇒ Object
- #authorize_include_directive ⇒ Object
- #authorize_remove_resource ⇒ Object
- #authorize_remove_to_many_relationship ⇒ Object
- #authorize_remove_to_one_relationship ⇒ Object
- #authorize_replace_fields ⇒ Object
- #authorize_replace_to_many_relationship ⇒ Object
- #authorize_replace_to_one_relationship ⇒ Object
- #authorize_show ⇒ Object
- #authorize_show_related_resource ⇒ Object
- #authorize_show_related_resources ⇒ Object
- #authorize_show_relationship ⇒ Object
Instance Method Details
#authorize_create_resource ⇒ Object
114 115 116 117 118 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 114 def source_class = @resource_klass._model_class .create_resource(source_class, ) end |
#authorize_create_to_many_relationship ⇒ Object
152 153 154 155 156 157 158 159 160 161 162 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 152 def source_record = @resource_klass.find_by_key( params[:resource_id], context: context )._model = model_class_for_relationship(params[:relationship_type].to_sym).find(params[:data]) .create_to_many_relationship(source_record, ) end |
#authorize_find ⇒ Object
46 47 48 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 46 def .find(@resource_klass._model_class) end |
#authorize_include_directive ⇒ Object
31 32 33 34 35 36 37 38 39 40 41 42 43 44 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 31 def return if result.is_a?(::JSONAPI::ErrorsOperationResult) resources = Array.wrap( if result.respond_to?(:resources) result.resources elsif result.respond_to?(:resource) result.resource end ) resources.each do |resource| (resource._model) end end |
#authorize_remove_resource ⇒ Object
120 121 122 123 124 125 126 127 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 120 def record = @resource_klass.find_by_key( operation_resource_id, context: context )._model .remove_resource(record) end |
#authorize_remove_to_many_relationship ⇒ Object
179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 179 def source_resource = @resource_klass.find_by_key( params[:resource_id], context: context ) source_record = source_resource._model = @resource_klass._relationship(params[:relationship_type].to_sym).resource_klass.find_by_key( params[:associated_key], context: context ) = ._model unless .nil? .remove_to_many_relationship( source_record, ) end |
#authorize_remove_to_one_relationship ⇒ Object
198 199 200 201 202 203 204 205 206 207 208 209 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 198 def source_resource = @resource_klass.find_by_key( params[:resource_id], context: context ) = source_resource.public_send(params[:relationship_type].to_sym) source_record = source_resource._model = ._model unless .nil? .remove_to_one_relationship(source_record, ) end |
#authorize_replace_fields ⇒ Object
105 106 107 108 109 110 111 112 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 105 def source_record = @resource_klass.find_by_key( params[:resource_id], context: context )._model .replace_fields(source_record, ) end |
#authorize_replace_to_many_relationship ⇒ Object
164 165 166 167 168 169 170 171 172 173 174 175 176 177 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 164 def source_resource = @resource_klass.find_by_key( params[:resource_id], context: context ) source_record = source_resource._model = source_resource.records_for(params[:relationship_type].to_sym) .replace_to_many_relationship( source_record, ) end |
#authorize_replace_to_one_relationship ⇒ Object
129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 129 def source_resource = @resource_klass.find_by_key( params[:resource_id], context: context ) source_record = source_resource._model = source_resource.records_for(params[:relationship_type].to_sym) unless params[:key_value].nil? = @resource_klass._relationship(params[:relationship_type].to_sym).resource_klass.find_by_key( params[:key_value], context: context ) = ._model unless .nil? end .replace_to_one_relationship( source_record, , ) end |
#authorize_show ⇒ Object
50 51 52 53 54 55 56 57 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 50 def record = @resource_klass.find_by_key( operation_resource_id, context: context )._model .show(record) end |
#authorize_show_related_resource ⇒ Object
82 83 84 85 86 87 88 89 90 91 92 93 94 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 82 def source_klass = params[:source_klass] source_id = params[:source_id] relationship_type = params[:relationship_type].to_sym source_resource = source_klass.find_by_key(source_id, context: context) = source_resource.public_send(relationship_type) source_record = source_resource._model = ._model unless .nil? .(source_record, ) end |
#authorize_show_related_resources ⇒ Object
96 97 98 99 100 101 102 103 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 96 def source_record = params[:source_klass].find_by_key( params[:source_id], context: context )._model .(source_record) end |
#authorize_show_relationship ⇒ Object
59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 |
# File 'lib/jsonapi/authorization/authorizing_processor.rb', line 59 def parent_resource = @resource_klass.find_by_key( params[:parent_key], context: context ) relationship = @resource_klass._relationship(params[:relationship_type].to_sym) = case relationship when JSONAPI::Relationship::ToOne parent_resource.public_send(params[:relationship_type].to_sym) when JSONAPI::Relationship::ToMany # Do nothing — already covered by policy scopes else raise "Unexpected relationship type: #{relationship.inspect}" end parent_record = parent_resource._model = ._model unless .nil? .show_relationship(parent_record, ) end |