Class: OpenLoam::Sso::OidcProvider

Inherits:
Object
  • Object
show all
Defined in:
lib/open_loam/sso/oidc_provider.rb

Overview

The real OIDC Authorization Code provider. Discovers the issuer's endpoints from its .well-known document, sends the user to the authorization endpoint, then exchanges the returned code for an access token and reads the claims from the userinfo endpoint.

Why userinfo rather than validating the id_token's JWT signature: these claims arrive over a server-to-server TLS channel WE opened, authenticated by the client_secret — the browser never touches them. Signature validation exists for a token you RECEIVE (the id_token, relayed via the browser); fetching userinfo over an authenticated back channel sidesteps hand-rolled JWKS verification for the prototype. Roadmap: full id_token + JWKS.

NOT exercised by the test suite (a FakeProvider is injected via OpenLoam::Sso.builder); live OIDC against a real IdP is verified manually.

Constant Summary collapse

SCOPE =
"openid email profile".freeze

Instance Method Summary collapse

Constructor Details

#initialize(record, redirect_uri:) ⇒ OidcProvider

Returns a new instance of OidcProvider.



20
21
22
23
# File 'lib/open_loam/sso/oidc_provider.rb', line 20

def initialize(record, redirect_uri:)
  @record = record
  @redirect_uri = redirect_uri
end

Instance Method Details

#authorization_url(state:, login_hint: nil) ⇒ Object



25
26
27
28
29
30
31
32
33
34
35
# File 'lib/open_loam/sso/oidc_provider.rb', line 25

def authorization_url(state:, login_hint: nil)
  params = {
    response_type: "code",
    client_id: @record.client_id,
    redirect_uri: @redirect_uri,
    scope: SCOPE,
    state: state
  }
  params[:login_hint] =  if .present?
  "#{discovery.fetch('authorization_endpoint')}?#{params.to_query}"
end

#exchange(code:) ⇒ Object



37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
# File 'lib/open_loam/sso/oidc_provider.rb', line 37

def exchange(code:)
  token = HttpClient.post_form(discovery.fetch("token_endpoint"), {
    grant_type: "authorization_code",
    code: code,
    redirect_uri: @redirect_uri,
    client_id: @record.client_id,
    client_secret: @record.client_secret
  })

  info = HttpClient.get_json(discovery.fetch("userinfo_endpoint"), bearer: token.fetch("access_token"))

  Claims.new(
    sub: info["sub"],
    email: info["email"],
    email_verified: info["email_verified"],
    name: info["name"],
    groups: Array(info["groups"])
  )
end