Class: OpenLoam::Sso::OidcProvider
- Inherits:
-
Object
- Object
- OpenLoam::Sso::OidcProvider
- Defined in:
- lib/open_loam/sso/oidc_provider.rb
Overview
The real OIDC Authorization Code provider. Discovers the issuer's endpoints from its .well-known document, sends the user to the authorization endpoint, then exchanges the returned code for an access token and reads the claims from the userinfo endpoint.
Why userinfo rather than validating the id_token's JWT signature: these claims arrive over a server-to-server TLS channel WE opened, authenticated by the client_secret — the browser never touches them. Signature validation exists for a token you RECEIVE (the id_token, relayed via the browser); fetching userinfo over an authenticated back channel sidesteps hand-rolled JWKS verification for the prototype. Roadmap: full id_token + JWKS.
NOT exercised by the test suite (a FakeProvider is injected via OpenLoam::Sso.builder); live OIDC against a real IdP is verified manually.
Constant Summary collapse
- SCOPE =
"openid email profile".freeze
Instance Method Summary collapse
- #authorization_url(state:, login_hint: nil) ⇒ Object
- #exchange(code:) ⇒ Object
-
#initialize(record, redirect_uri:) ⇒ OidcProvider
constructor
A new instance of OidcProvider.
Constructor Details
#initialize(record, redirect_uri:) ⇒ OidcProvider
Returns a new instance of OidcProvider.
20 21 22 23 |
# File 'lib/open_loam/sso/oidc_provider.rb', line 20 def initialize(record, redirect_uri:) @record = record @redirect_uri = redirect_uri end |
Instance Method Details
#authorization_url(state:, login_hint: nil) ⇒ Object
25 26 27 28 29 30 31 32 33 34 35 |
# File 'lib/open_loam/sso/oidc_provider.rb', line 25 def (state:, login_hint: nil) params = { response_type: "code", client_id: @record.client_id, redirect_uri: @redirect_uri, scope: SCOPE, state: state } params[:login_hint] = login_hint if login_hint.present? "#{discovery.fetch('authorization_endpoint')}?#{params.to_query}" end |
#exchange(code:) ⇒ Object
37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 |
# File 'lib/open_loam/sso/oidc_provider.rb', line 37 def exchange(code:) token = HttpClient.post_form(discovery.fetch("token_endpoint"), { grant_type: "authorization_code", code: code, redirect_uri: @redirect_uri, client_id: @record.client_id, client_secret: @record.client_secret }) info = HttpClient.get_json(discovery.fetch("userinfo_endpoint"), bearer: token.fetch("access_token")) Claims.new( sub: info["sub"], email: info["email"], email_verified: info["email_verified"], name: info["name"], groups: Array(info["groups"]) ) end |