Class: Api::BaseController
- Inherits:
-
ActionController::API
- Object
- ActionController::API
- Api::BaseController
- Defined in:
- lib/generators/open_loam/install/templates/api_base_controller.rb
Overview
Base class for every JSON endpoint. Authentication is a bearer token:
curl -H "Authorization: Bearer <token>" http://localhost:3000/api/equipment
A token identifies one user in one tenant, and OpenLoam::ApiToken.authenticate
establishes both in OpenLoam::Current before any action runs. From that point
on this is ordinary tenant-scoped OpenLoam code: every query is filtered, every
write is audited, every policy applies — the API is not a side door.
Finding a token is the one lookup that cannot start from a tenant (the token is what reveals the tenant), which is why it lives in the gem rather than here: host app code must never reach across tenants.
Class Method Summary collapse
Class Method Details
.skip_authorization!(reason, **options) ⇒ Object
22 23 24 25 26 |
# File 'lib/generators/open_loam/install/templates/api_base_controller.rb', line 22 def self.(reason, **) raise ArgumentError, "skip_authorization! needs a reason" if reason.to_s.strip.empty? skip_after_action :verify_authorized!, ** end |