Class: OpenLoam::SsoProvider

Inherits:
TenantRecord
  • Object
show all
Includes:
Auditable, Encryptable
Defined in:
app/models/open_loam/sso_provider.rb

Overview

A tenant's connection to an external identity provider (OIDC). Per-tenant config: each tenant/org wires its OWN IdP, so the client_secret is encrypted under the tenant key (the default Encryptable scope) — unlike MFA, which is user-keyed. Home-realm discovery matches an email domain to the owning provider at the sign-in page (see OpenLoam::Sso.provider_for).

Constant Summary

Constants included from Auditable

Auditable::IGNORED_ATTRIBUTES

Instance Method Summary collapse

Methods included from Encryptable

#open_loam_reencrypt!

Instance Method Details

#domain_verified? ⇒ Boolean

Until ownership is proven, HRD skips the provider and OpenLoam::Sso refuses to link an existing account through it.

Returns:

  • (Boolean)


42
# File 'app/models/open_loam/sso_provider.rb', line 42

def domain_verified? = domain_verified_at.present?

#group_roles ⇒ Object

IdP group -> OpenLoam role, first match wins; falls back to jit_role.



50
51
52
# File 'app/models/open_loam/sso_provider.rb', line 50

def group_roles
  group_role_map.is_a?(Hash) ? group_role_map : {}
end

#verify_domain!(at: Time.current) ⇒ Object

Operator entry point (rake open_loam:sso:verify_domain), off the admin path.



45
46
47
# File 'app/models/open_loam/sso_provider.rb', line 45

def verify_domain!(at: Time.current)
  update!(domain_verified_at: at)
end