Class: OpenLoam::Sso::FakeProvider
- Inherits:
-
Object
- Object
- OpenLoam::Sso::FakeProvider
- Defined in:
- lib/open_loam/sso/fake_provider.rb
Overview
An OFFLINE stand-in for a real IdP — for the demo and the test suite ONLY,
NEVER production. authorization_url loops straight back to our own
callback carrying the login email (as the "code"), so the whole SSO
round-trip runs with no network. exchange returns verified claims for
that email.
Tests drive the security paths through two class-level overrides (reset in
teardown): force_email_verified = false to prove an unverified email is
refused, and claims_override to inject arbitrary claims (a fixed sub,
IdP groups for role mapping, a different email).
Class Attribute Summary collapse
-
.claims_override ⇒ Object
Returns the value of attribute claims_override.
-
.force_email_verified ⇒ Object
Returns the value of attribute force_email_verified.
Class Method Summary collapse
Instance Method Summary collapse
- #authorization_url(state:, login_hint: nil) ⇒ Object
- #exchange(code:) ⇒ Object
-
#initialize(record, redirect_uri:) ⇒ FakeProvider
constructor
A new instance of FakeProvider.
Constructor Details
#initialize(record, redirect_uri:) ⇒ FakeProvider
Returns a new instance of FakeProvider.
25 26 27 28 |
# File 'lib/open_loam/sso/fake_provider.rb', line 25 def initialize(record, redirect_uri:) @record = record @redirect_uri = redirect_uri end |
Class Attribute Details
.claims_override ⇒ Object
Returns the value of attribute claims_override.
17 18 19 |
# File 'lib/open_loam/sso/fake_provider.rb', line 17 def claims_override @claims_override end |
.force_email_verified ⇒ Object
Returns the value of attribute force_email_verified.
17 18 19 |
# File 'lib/open_loam/sso/fake_provider.rb', line 17 def force_email_verified @force_email_verified end |
Class Method Details
.reset! ⇒ Object
19 20 21 22 |
# File 'lib/open_loam/sso/fake_provider.rb', line 19 def reset! self.claims_override = nil self.force_email_verified = nil end |
Instance Method Details
#authorization_url(state:, login_hint: nil) ⇒ Object
30 31 32 33 34 |
# File 'lib/open_loam/sso/fake_provider.rb', line 30 def (state:, login_hint: nil) uri = URI(@redirect_uri) uri.query = { code: Base64.urlsafe_encode64(login_hint.to_s), state: state }.to_query uri.to_s end |
#exchange(code:) ⇒ Object
36 37 38 39 40 41 42 43 44 45 46 47 48 |
# File 'lib/open_loam/sso/fake_provider.rb', line 36 def exchange(code:) return self.class.claims_override if self.class.claims_override email = Base64.urlsafe_decode64(code.to_s) verified = self.class.force_email_verified.nil? ? true : self.class.force_email_verified Claims.new( sub: "fake|#{email}", email: email, email_verified: verified, name: email.split("@").first, groups: [] ) end |