Class: OpenLoam::InboundWebhookSource

Inherits:
TenantRecord
  • Object
show all
Defined in:
app/models/open_loam/inbound_webhook_source.rb

Overview

A registered external system allowed to POST webhooks INTO this tenant — the inbound sibling of OpenLoam::WebhookEndpoint (which delivers events OUT). The token is the unguessable URL id (/webhooks/:token) that identifies the source; the secret is the HMAC key that AUTHENTICATES each call. Identity is not authority: rotating either is supported from the admin.

On a verified delivery, OpenLoam publishes event_name onto the domain event bus with a reference to the stored OpenLoam::InboundWebhookDelivery, so durable subscribers (OpenLoam::DurableEvents) react — the payload itself lives on the row.

Constant Summary collapse

DEFAULT_SIGNATURE_HEADER =
"X-OpenLoam-Signature".freeze
DEFAULT_TOLERANCE =

seconds

300

Class Method Summary collapse

Instance Method Summary collapse

Class Method Details

.resolve(raw_token) ⇒ Object

THE blessed cross-tenant lookup (see OpenLoam::ApiToken.authenticate): a public inbound request arrives with no tenant context — the token in the URL is how it discovers its tenant. Establishes OpenLoam::Current.tenant (never an actor: the sender is a machine, not a user) and returns the ACTIVE source, or nil.



39
40
41
42
43
44
45
46
47
# File 'app/models/open_loam/inbound_webhook_source.rb', line 39

def self.resolve(raw_token)
  return nil if raw_token.blank?

  source = unscoped.find_by(token: raw_token)
  return nil unless source&.active?

  OpenLoam::Current.tenant = source.tenant
  source
end

Instance Method Details

#rotate_secret! ⇒ Object



53
# File 'app/models/open_loam/inbound_webhook_source.rb', line 53

def rotate_secret! = update!(secret: SecureRandom.hex(32))

#rotate_token! ⇒ Object



52
# File 'app/models/open_loam/inbound_webhook_source.rb', line 52

def rotate_token!  = update!(token: SecureRandom.hex(24))

#signature_header_key ⇒ Object



49
# File 'app/models/open_loam/inbound_webhook_source.rb', line 49

def signature_header_key = signature_header.presence || DEFAULT_SIGNATURE_HEADER

#tolerance ⇒ Object



50
# File 'app/models/open_loam/inbound_webhook_source.rb', line 50

def tolerance = (timestamp_tolerance.presence || DEFAULT_TOLERANCE).to_i