Module: OpenLoam

Defined in:
lib/open_loam.rb,
lib/open_loam/csv.rb,
lib/open_loam/mcp.rb,
lib/open_loam/sso.rb,
lib/open_loam/bulk.rb,
lib/open_loam/cron.rb,
lib/open_loam/eval.rb,
lib/open_loam/totp.rb,
lib/open_loam/undo.rb,
lib/open_loam/base32.rb,
lib/open_loam/engine.rb,
lib/open_loam/errors.rb,
lib/open_loam/events.rb,
lib/open_loam/export.rb,
lib/open_loam/import.rb,
lib/open_loam/policy.rb,
lib/open_loam/search.rb,
lib/open_loam/configs.rb,
lib/open_loam/current.rb,
lib/open_loam/version.rb,
lib/open_loam/widgets.rb,
lib/open_loam/eventful.rb,
lib/open_loam/features.rb,
lib/open_loam/open_api.rb,
lib/open_loam/progress.rb,
lib/open_loam/webhooks.rb,
lib/open_loam/workflow.rb,
lib/open_loam/auditable.rb,
lib/open_loam/dashboard.rb,
lib/open_loam/enrichers.rb,
lib/open_loam/event_log.rb,
lib/open_loam/lifecycle.rb,
lib/open_loam/overrides.rb,
lib/open_loam/scheduler.rb,
lib/open_loam/telemetry.rb,
lib/open_loam/attachable.rb,
lib/open_loam/encryption.rb,
lib/open_loam/mcp/server.rb,
lib/open_loam/searchable.rb,
lib/open_loam/sso/claims.rb,
lib/open_loam/commentable.rb,
lib/open_loam/encryptable.rb,
lib/open_loam/permissions.rb,
lib/open_loam/dictionaries.rb,
lib/open_loam/event_stream.rb,
lib/open_loam/outbound_url.rb,
lib/open_loam/perspectives.rb,
lib/open_loam/record_locks.rb,
lib/open_loam/test_helpers.rb,
lib/open_loam/translatable.rb,
app/models/open_loam/config.rb,
app/models/open_loam/tenant.rb,
lib/open_loam/auth_throttle.rb,
lib/open_loam/custom_fields.rb,
lib/open_loam/generated_key.rb,
lib/open_loam/notifications.rb,
lib/open_loam/search/driver.rb,
lib/open_loam/tenant_record.rb,
app/models/open_loam/comment.rb,
lib/open_loam/business_rules.rb,
lib/open_loam/durable_events.rb,
lib/open_loam/soft_deletable.rb,
lib/open_loam/pending_actions.rb,
lib/open_loam/sso/http_client.rb,
app/models/open_loam/api_token.rb,
lib/open_loam/inbound_webhooks.rb,
app/models/open_loam/dictionary.rb,
app/models/open_loam/membership.rb,
lib/open_loam/encryption/cipher.rb,
lib/open_loam/sso/fake_provider.rb,
lib/open_loam/sso/oidc_provider.rb,
app/models/open_loam/perspective.rb,
app/models/open_loam/record_lock.rb,
app/models/open_loam/translation.rb,
lib/open_loam/custom_field_index.rb,
lib/open_loam/search/like_driver.rb,
app/models/open_loam/audit_record.rb,
app/models/open_loam/auth_attempt.rb,
app/models/open_loam/event_record.rb,
app/models/open_loam/notification.rb,
app/models/open_loam/progress_job.rb,
app/models/open_loam/search_token.rb,
app/models/open_loam/sso_identity.rb,
app/models/open_loam/sso_provider.rb,
lib/open_loam/search/token_driver.rb,
app/models/open_loam/business_rule.rb,
app/models/open_loam/scheduled_job.rb,
app/models/open_loam/event_delivery.rb,
app/models/open_loam/mfa_credential.rb,
app/models/open_loam/pending_action.rb,
lib/open_loam/business_rules/actions.rb,
app/jobs/open_loam/event_delivery_job.rb,
app/models/open_loam/dashboard_widget.rb,
app/models/open_loam/dictionary_entry.rb,
app/models/open_loam/field_definition.rb,
app/models/open_loam/webhook_endpoint.rb,
lib/open_loam/encryption/key_provider.rb,
app/jobs/open_loam/event_log_prune_job.rb,
app/models/open_loam/business_rule_run.rb,
lib/open_loam/business_rules/condition.rb,
app/jobs/open_loam/webhook_delivery_job.rb,
app/models/open_loam/custom_field_value.rb,
app/jobs/open_loam/custom_field_reindex_job.rb,
app/models/open_loam/inbound_webhook_source.rb,
lib/generators/open_loam/primary_key_options.rb,
app/jobs/open_loam/event_redelivery_sweep_job.rb,
app/models/open_loam/inbound_webhook_delivery.rb,
lib/generators/open_loam/entity/entity_generator.rb,
lib/generators/open_loam/install/install_generator.rb

Defined Under Namespace

Modules: Attachable, Auditable, AuthThrottle, Base32, Bulk, BusinessRules, Commentable, Configs, Cron, Csv, CustomFieldIndex, CustomFields, Dashboard, Dictionaries, DurableEvents, Encryptable, Encryption, Enrichers, Eval, EventLog, EventStream, Eventful, Events, Export, Features, GeneratedKey, Generators, Import, InboundWebhooks, Lifecycle, Mcp, Notifications, OpenApi, OutboundUrl, Overrides, PendingActions, Permissions, Perspectives, Progress, RecordLocks, Scheduler, Search, Searchable, SoftDeletable, Sso, Telemetry, TestHelpers, Totp, Translatable, Undo, Webhooks, Widgets, Workflow Classes: ApiToken, AuditRecord, AuthAttempt, AuthorizationNotPerformedError, BusinessRule, BusinessRuleRun, Comment, Config, Current, CustomFieldReindexJob, CustomFieldValue, DashboardWidget, Dictionary, DictionaryEntry, Engine, Error, EventDelivery, EventDeliveryJob, EventLogPruneJob, EventRecord, EventRedeliverySweepJob, FeatureDisabledError, FieldAccessError, FieldDefinition, InboundWebhookDelivery, InboundWebhookSource, InvalidEventNameError, InvalidTransitionError, Membership, MfaCredential, MissingTenantError, NotAuthorizedError, Notification, PendingAction, Perspective, Policy, ProgressJob, RecordLock, ScheduledJob, SearchToken, SsoIdentity, SsoProvider, Tenant, TenantRecord, TransitionVetoedError, Translation, UnknownCustomFieldError, WebhookDeliveryJob, WebhookEndpoint

Constant Summary collapse

VERSION =
"0.3.0"

Class Method Summary collapse

Class Method Details

.actor ⇒ Object



63
64
65
# File 'lib/open_loam.rb', line 63

def self.actor
  Current.actor
end

.as_tenant(tenant, actor: nil) ⇒ Object

Run a block inside a tenant (and optional actor) context, restoring the previous context afterwards. The one blessed way to switch tenants.



99
100
101
102
103
104
105
106
107
108
# File 'lib/open_loam.rb', line 99

def self.as_tenant(tenant, actor: nil)
  previous_tenant = Current.tenant
  previous_actor = Current.actor
  Current.tenant = tenant
  Current.actor = actor if actor
  yield
ensure
  Current.tenant = previous_tenant
  Current.actor = previous_actor
end

.broadcast_events ⇒ Object



184
# File 'lib/open_loam/lifecycle.rb', line 184

def self.broadcast_events = Lifecycle.broadcast_events

.broadcast_events=(patterns) ⇒ Object



185
186
187
# File 'lib/open_loam/lifecycle.rb', line 185

def self.broadcast_events=(patterns)
  Lifecycle.broadcast_events = patterns
end

.can?(permission, role: nil) ⇒ Boolean

Feature-string permission check for the current actor's role (see OpenLoam::Permissions) — deny-by-default, wildcard-aware. role: overrides the actor's role. Returns false with no actor/role.

Returns:

  • (Boolean)


70
71
72
73
# File 'lib/open_loam.rb', line 70

def self.can?(permission, role: nil)
  role ||= Current.actor && OpenLoam::Membership.find_by(user_id: Current.actor.id)&.role
  OpenLoam::Permissions.allow?(role, permission)
end

.config_defaults ⇒ Object



176
# File 'lib/open_loam/lifecycle.rb', line 176

def self.config_defaults = Lifecycle.config_defaults

.config_defaults=(defaults) ⇒ Object



177
178
179
# File 'lib/open_loam/lifecycle.rb', line 177

def self.config_defaults=(defaults)
  Lifecycle.config_defaults = defaults
end

.default_locale ⇒ Object



204
# File 'lib/open_loam/lifecycle.rb', line 204

def self.default_locale = Lifecycle.default_locale

.default_roles ⇒ Object



172
# File 'lib/open_loam/lifecycle.rb', line 172

def self.default_roles = Lifecycle.default_roles

.default_roles=(roles) ⇒ Object



173
174
175
# File 'lib/open_loam/lifecycle.rb', line 173

def self.default_roles=(roles)
  Lifecycle.default_roles = roles
end

.event_log_retention ⇒ Object



192
# File 'lib/open_loam/lifecycle.rb', line 192

def self.event_log_retention = Lifecycle.event_log_retention

.event_log_retention=(duration) ⇒ Object



193
194
195
# File 'lib/open_loam/lifecycle.rb', line 193

def self.event_log_retention=(duration)
  Lifecycle.event_log_retention = duration
end

.feature_defaults ⇒ Object



180
# File 'lib/open_loam/lifecycle.rb', line 180

def self.feature_defaults = Lifecycle.feature_defaults

.feature_defaults=(defaults) ⇒ Object



181
182
183
# File 'lib/open_loam/lifecycle.rb', line 181

def self.feature_defaults=(defaults)
  Lifecycle.feature_defaults = defaults
end

.locale ⇒ Object



205
# File 'lib/open_loam/lifecycle.rb', line 205

def self.locale = Lifecycle.locale

.locale=(code) ⇒ Object



206
207
208
# File 'lib/open_loam/lifecycle.rb', line 206

def self.locale=(code)
  Lifecycle.locale = code
end

.locales ⇒ Object



196
# File 'lib/open_loam/lifecycle.rb', line 196

def self.locales = Lifecycle.locales

.locales=(codes) ⇒ Object



197
198
199
# File 'lib/open_loam/lifecycle.rb', line 197

def self.locales=(codes)
  Lifecycle.locales = codes
end

.mutation_mode ⇒ Object

The approval-gate seam. When a caller runs under :confirm (an MCP tool acting for an AI agent), a write should be STAGED for human approval via OpenLoam::PendingActions.stage instead of committed. OpenLoam does not intercept Active Record globally — this is the documented hook a write path checks.



79
80
81
# File 'lib/open_loam.rb', line 79

def self.mutation_mode
  Current.mutation_mode || :direct
end

.on_tenant_created(&block) ⇒ Object

The public surface is on OpenLoam itself — apps and agents write OpenLoam.on_tenant_created, never OpenLoam::Lifecycle.on_tenant_created.



169
# File 'lib/open_loam/lifecycle.rb', line 169

def self.on_tenant_created(&block) = Lifecycle.on_tenant_created(&block)

.require_confirmation? ⇒ Boolean

Returns:

  • (Boolean)


83
84
85
# File 'lib/open_loam.rb', line 83

def self.require_confirmation?
  mutation_mode == :confirm
end

.schedulable_jobs ⇒ Object



200
# File 'lib/open_loam/lifecycle.rb', line 200

def self.schedulable_jobs = Lifecycle.schedulable_jobs

.schedulable_jobs=(names) ⇒ Object



201
202
203
# File 'lib/open_loam/lifecycle.rb', line 201

def self.schedulable_jobs=(names)
  Lifecycle.schedulable_jobs = names
end

.sync_tenants! ⇒ Object



171
# File 'lib/open_loam/lifecycle.rb', line 171

def self.sync_tenants! = Lifecycle.sync_tenants!

.tenant ⇒ Object



59
60
61
# File 'lib/open_loam.rb', line 59

def self.tenant
  Current.tenant
end

.tenant! ⇒ Object

The current tenant, or a loud failure. This is THE guardrail: tenant-scoped code paths call this, so a missing tenant context can never silently widen a query to all tenants.



55
56
57
# File 'lib/open_loam.rb', line 55

def self.tenant!
  Current.tenant or raise MissingTenantError
end

.tenant_created_callbacks ⇒ Object



170
# File 'lib/open_loam/lifecycle.rb', line 170

def self.tenant_created_callbacks = Lifecycle.tenant_created_callbacks

.uncaptured_events ⇒ Object



188
# File 'lib/open_loam/lifecycle.rb', line 188

def self.uncaptured_events = Lifecycle.uncaptured_events

.uncaptured_events=(patterns) ⇒ Object



189
190
191
# File 'lib/open_loam/lifecycle.rb', line 189

def self.uncaptured_events=(patterns)
  Lifecycle.uncaptured_events = patterns
end

.with_confirmation ⇒ Object

Run a block with writes gated for approval. The one blessed way to enter confirm-mode; restores the previous mode afterwards.



89
90
91
92
93
94
95
# File 'lib/open_loam.rb', line 89

def self.with_confirmation
  previous = Current.mutation_mode
  Current.mutation_mode = :confirm
  yield
ensure
  Current.mutation_mode = previous
end