Class: OpenLoam::Sso::FakeProvider

Inherits:
Object
  • Object
show all
Defined in:
lib/open_loam/sso/fake_provider.rb

Overview

An OFFLINE stand-in for a real IdP — for the demo and the test suite ONLY, NEVER production. authorization_url loops straight back to our own callback carrying the login email (as the "code"), so the whole SSO round-trip runs with no network. exchange returns verified claims for that email.

Tests drive the security paths through two class-level overrides (reset in teardown): force_email_verified = false to prove an unverified email is refused, and claims_override to inject arbitrary claims (a fixed sub, IdP groups for role mapping, a different email).

Class Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(record, redirect_uri:) ⇒ FakeProvider

Returns a new instance of FakeProvider.



25
26
27
28
# File 'lib/open_loam/sso/fake_provider.rb', line 25

def initialize(record, redirect_uri:)
  @record = record
  @redirect_uri = redirect_uri
end

Class Attribute Details

.claims_override ⇒ Object

Returns the value of attribute claims_override.



17
18
19
# File 'lib/open_loam/sso/fake_provider.rb', line 17

def claims_override
  @claims_override
end

.force_email_verified ⇒ Object

Returns the value of attribute force_email_verified.



17
18
19
# File 'lib/open_loam/sso/fake_provider.rb', line 17

def force_email_verified
  @force_email_verified
end

Class Method Details

.reset! ⇒ Object



19
20
21
22
# File 'lib/open_loam/sso/fake_provider.rb', line 19

def reset!
  self.claims_override = nil
  self.force_email_verified = nil
end

Instance Method Details

#authorization_url(state:, login_hint: nil) ⇒ Object



30
31
32
33
34
# File 'lib/open_loam/sso/fake_provider.rb', line 30

def authorization_url(state:, login_hint: nil)
  uri = URI(@redirect_uri)
  uri.query = { code: Base64.urlsafe_encode64(.to_s), state: state }.to_query
  uri.to_s
end

#exchange(code:) ⇒ Object



36
37
38
39
40
41
42
43
44
45
46
47
48
# File 'lib/open_loam/sso/fake_provider.rb', line 36

def exchange(code:)
  return self.class.claims_override if self.class.claims_override

  email = Base64.urlsafe_decode64(code.to_s)
  verified = self.class.force_email_verified.nil? ? true : self.class.force_email_verified
  Claims.new(
    sub: "fake|#{email}",
    email: email,
    email_verified: verified,
    name: email.split("@").first,
    groups: []
  )
end