Class: Admin::SudoController
- Inherits:
-
BaseController
- Object
- ActionController::Base
- BaseController
- Admin::SudoController
- Defined in:
- lib/generators/open_loam/install/templates/admin/sudo_controller.rb
Overview
The step-up ("sudo") re-challenge. A sensitive action calls require_sudo!, which detours here when the last authentication is stale; a correct password (or TOTP code, if the user has MFA) stamps a fresh sudo timestamp and returns to wherever they were headed.
Constant Summary
Constants included from Pagination
Instance Method Summary collapse
Methods inherited from BaseController
Methods included from Pagination
Instance Method Details
#create ⇒ Object
12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 |
# File 'lib/generators/open_loam/install/templates/admin/sudo_controller.rb', line 12 def create identifier = "#{current_actor.email}:sudo" # a distinct throttle bucket from login if OpenLoam::AuthThrottle.locked?(identifier) @error = "Too many attempts. Try again later." return render :new, status: :too_many_requests end if reauthenticated? OpenLoam::AuthThrottle.clear(identifier, kind: "sudo") session[:sudo_at] = Time.now.to_i redirect_to(session.delete(:sudo_return_to).presence || admin_root_path, notice: "Re-authenticated — you can complete the action now.") else OpenLoam::AuthThrottle.record_failure(identifier, kind: "sudo", ip: request.remote_ip) @error = "That did not verify. Try again." render :new, status: :unauthorized end end |
#new ⇒ Object
9 10 |
# File 'lib/generators/open_loam/install/templates/admin/sudo_controller.rb', line 9 def new end |