Module: OpenLoam::Sso::HttpClient

Defined in:
lib/open_loam/sso/http_client.rb

Overview

The one place SSO talks to the network — kept tiny and isolated so the rest of the flow is pure. Only OpenLoam::Sso::OidcProvider uses it, and the test suite injects a FakeProvider instead, so this is never exercised offline.

Class Method Summary collapse

Class Method Details

.checked(url) ⇒ Object

The issuer is typed by a tenant manager, so these URLs are as untrusted as a webhook endpoint's. https is mandatory here rather than merely allowed: the client_secret and the code exchange travel over it.



30
31
32
33
34
# File 'lib/open_loam/sso/http_client.rb', line 30

def checked(url)
  OpenLoam::OutboundUrl.resolve!(url, require_https: true)
rescue OpenLoam::OutboundUrl::BlockedError => error
  raise OpenLoam::Sso::Error, "identity provider URL refused: #{error.message}"
end

.get_json(url, bearer: nil) ⇒ Object



12
13
14
15
16
17
# File 'lib/open_loam/sso/http_client.rb', line 12

def get_json(url, bearer: nil)
  uri, address = checked(url)
  request = Net::HTTP::Get.new(uri)
  request["Authorization"] = "Bearer #{bearer}" if bearer
  parse(perform(uri, address, request))
end

.parse(response) ⇒ Object



42
43
44
45
46
47
48
# File 'lib/open_loam/sso/http_client.rb', line 42

def parse(response)
  unless response.is_a?(Net::HTTPSuccess)
    raise OpenLoam::Sso::Error, "identity provider returned #{response.code}"
  end

  JSON.parse(response.body)
end

.perform(uri, address, request) ⇒ Object



36
37
38
39
40
# File 'lib/open_loam/sso/http_client.rb', line 36

def perform(uri, address, request)
  Net::HTTP.start(uri.host, uri.port, use_ssl: true, ipaddr: address) do |http|
    http.request(request)
  end
end

.post_form(url, params) ⇒ Object



19
20
21
22
23
24
25
# File 'lib/open_loam/sso/http_client.rb', line 19

def post_form(url, params)
  uri, address = checked(url)
  request = Net::HTTP::Post.new(uri)
  request.set_form_data(params)
  request["Accept"] = "application/json"
  parse(perform(uri, address, request))
end