Module: OpenLoam::Sso::HttpClient
- Defined in:
- lib/open_loam/sso/http_client.rb
Overview
The one place SSO talks to the network — kept tiny and isolated so the rest of the flow is pure. Only OpenLoam::Sso::OidcProvider uses it, and the test suite injects a FakeProvider instead, so this is never exercised offline.
Class Method Summary collapse
-
.checked(url) ⇒ Object
The issuer is typed by a tenant manager, so these URLs are as untrusted as a webhook endpoint's.
- .get_json(url, bearer: nil) ⇒ Object
- .parse(response) ⇒ Object
- .perform(uri, address, request) ⇒ Object
- .post_form(url, params) ⇒ Object
Class Method Details
.checked(url) ⇒ Object
The issuer is typed by a tenant manager, so these URLs are as untrusted as a webhook endpoint's. https is mandatory here rather than merely allowed: the client_secret and the code exchange travel over it.
30 31 32 33 34 |
# File 'lib/open_loam/sso/http_client.rb', line 30 def checked(url) OpenLoam::OutboundUrl.resolve!(url, require_https: true) rescue OpenLoam::OutboundUrl::BlockedError => error raise OpenLoam::Sso::Error, "identity provider URL refused: #{error.}" end |
.get_json(url, bearer: nil) ⇒ Object
12 13 14 15 16 17 |
# File 'lib/open_loam/sso/http_client.rb', line 12 def get_json(url, bearer: nil) uri, address = checked(url) request = Net::HTTP::Get.new(uri) request["Authorization"] = "Bearer #{bearer}" if bearer parse(perform(uri, address, request)) end |
.parse(response) ⇒ Object
42 43 44 45 46 47 48 |
# File 'lib/open_loam/sso/http_client.rb', line 42 def parse(response) unless response.is_a?(Net::HTTPSuccess) raise OpenLoam::Sso::Error, "identity provider returned #{response.code}" end JSON.parse(response.body) end |
.perform(uri, address, request) ⇒ Object
36 37 38 39 40 |
# File 'lib/open_loam/sso/http_client.rb', line 36 def perform(uri, address, request) Net::HTTP.start(uri.host, uri.port, use_ssl: true, ipaddr: address) do |http| http.request(request) end end |
.post_form(url, params) ⇒ Object
19 20 21 22 23 24 25 |
# File 'lib/open_loam/sso/http_client.rb', line 19 def post_form(url, params) uri, address = checked(url) request = Net::HTTP::Post.new(uri) request.set_form_data(params) request["Accept"] = "application/json" parse(perform(uri, address, request)) end |