Class: Admin::SudoController

Inherits:
BaseController show all
Defined in:
lib/generators/open_loam/install/templates/admin/sudo_controller.rb

Overview

The step-up ("sudo") re-challenge. A sensitive action calls require_sudo!, which detours here when the last authentication is stale; a correct password (or TOTP code, if the user has MFA) stamps a fresh sudo timestamp and returns to wherever they were headed.

Constant Summary

Constants included from Pagination

Pagination::PER_PAGE

Instance Method Summary collapse

Methods inherited from BaseController

skip_authorization!

Methods included from Pagination

#paginate

Instance Method Details

#create ⇒ Object



12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
# File 'lib/generators/open_loam/install/templates/admin/sudo_controller.rb', line 12

def create
  identifier = "#{current_actor.email}:sudo"  # a distinct throttle bucket from login

  if OpenLoam::AuthThrottle.locked?(identifier)
    @error = "Too many attempts. Try again later."
    return render :new, status: :too_many_requests
  end

  if reauthenticated?
    OpenLoam::AuthThrottle.clear(identifier, kind: "sudo")
    session[:sudo_at] = Time.now.to_i
    redirect_to(session.delete(:sudo_return_to).presence || admin_root_path,
                notice: "Re-authenticated — you can complete the action now.")
  else
    OpenLoam::AuthThrottle.record_failure(identifier, kind: "sudo", ip: request.remote_ip)
    @error = "That did not verify. Try again."
    render :new, status: :unauthorized
  end
end

#new ⇒ Object



9
10
# File 'lib/generators/open_loam/install/templates/admin/sudo_controller.rb', line 9

def new
end