Class: Api::BaseController

Inherits:
ActionController::API
  • Object
show all
Defined in:
lib/generators/open_loam/install/templates/api_base_controller.rb

Overview

Base class for every JSON endpoint. Authentication is a bearer token:

curl -H "Authorization: Bearer <token>" http://localhost:3000/api/equipment

A token identifies one user in one tenant, and OpenLoam::ApiToken.authenticate establishes both in OpenLoam::Current before any action runs. From that point on this is ordinary tenant-scoped OpenLoam code: every query is filtered, every write is audited, every policy applies — the API is not a side door.

Finding a token is the one lookup that cannot start from a tenant (the token is what reveals the tenant), which is why it lives in the gem rather than here: host app code must never reach across tenants.

Class Method Summary collapse

Class Method Details

.skip_authorization!(reason, **options) ⇒ Object

Raises:

  • (ArgumentError)


22
23
24
25
26
# File 'lib/generators/open_loam/install/templates/api_base_controller.rb', line 22

def self.skip_authorization!(reason, **options)
  raise ArgumentError, "skip_authorization! needs a reason" if reason.to_s.strip.empty?

  skip_after_action :verify_authorized!, **options
end