Class: OpenLoam::SsoProvider
- Inherits:
-
TenantRecord
- Object
- TenantRecord
- OpenLoam::SsoProvider
- Includes:
- Auditable, Encryptable
- Defined in:
- app/models/open_loam/sso_provider.rb
Overview
A tenant's connection to an external identity provider (OIDC). Per-tenant
config: each tenant/org wires its OWN IdP, so the client_secret is encrypted
under the tenant key (the default Encryptable scope) — unlike MFA, which is
user-keyed. Home-realm discovery matches an email domain to the owning
provider at the sign-in page (see OpenLoam::Sso.provider_for).
Constant Summary
Constants included from Auditable
Instance Method Summary collapse
-
#domain_verified? ⇒ Boolean
Until ownership is proven, HRD skips the provider and OpenLoam::Sso refuses to link an existing account through it.
-
#group_roles ⇒ Object
IdP group -> OpenLoam role, first match wins; falls back to jit_role.
-
#verify_domain!(at: Time.current) ⇒ Object
Operator entry point (rake open_loam:sso:verify_domain), off the admin path.
Methods included from Encryptable
Instance Method Details
#domain_verified? ⇒ Boolean
Until ownership is proven, HRD skips the provider and OpenLoam::Sso refuses to link an existing account through it.
42 |
# File 'app/models/open_loam/sso_provider.rb', line 42 def domain_verified? = domain_verified_at.present? |
#group_roles ⇒ Object
IdP group -> OpenLoam role, first match wins; falls back to jit_role.
50 51 52 |
# File 'app/models/open_loam/sso_provider.rb', line 50 def group_roles group_role_map.is_a?(Hash) ? group_role_map : {} end |
#verify_domain!(at: Time.current) ⇒ Object
Operator entry point (rake open_loam:sso:verify_domain), off the admin path.
45 46 47 |
# File 'app/models/open_loam/sso_provider.rb', line 45 def verify_domain!(at: Time.current) update!(domain_verified_at: at) end |