Class: RubySMB::Gss::Provider::Multi

Inherits:
Base
  • Object
show all
Defined in:
lib/ruby_smb/gss/provider/multi.rb

Overview

A GSS provider that offers more than one authentication mechanism to the client and routes each request to whichever of its sub-providers understands the mechanism the client selected.

SPNEGO exists so that a client and server can agree on a mechanism, but a server that only ever advertises one has nothing to negotiate. This provider advertises the mechanisms of every provider it holds, in the order they were given, so a client can pick the one it prefers.

Examples:

Offer Kerberos, falling back to NTLM

provider = RubySMB::Gss::Provider::Multi.new([kerberos_provider, ntlm_provider])
RubySMB::Server.new(gss_provider: provider)

Defined Under Namespace

Classes: Authenticator

Instance Attribute Summary collapse

Instance Method Summary collapse

Methods inherited from Base

#supports_mech_type?

Constructor Details

#initialize(providers) ⇒ Multi

Returns a new instance of Multi.

Parameters:

  • providers (Array<Provider::Base>) —

    the providers to offer, in preference order (most preferred first).

Raises:

  • (ArgumentError)


19
20
21
22
23
# File 'lib/ruby_smb/gss/provider/multi.rb', line 19

def initialize(providers)
  raise ArgumentError, 'at least one provider is required' if providers.nil? || providers.empty?

  @providers = providers.dup.freeze
end

Instance Attribute Details

#providers ⇒ Array<Provider::Base> (readonly)

Returns the providers this instance will route between.

Returns:

  • (Array<Provider::Base>) —

    the providers this instance will route between.



26
27
28
# File 'lib/ruby_smb/gss/provider/multi.rb', line 26

def providers
  @providers
end

Instance Method Details

#allow_anonymous ⇒ Object



50
51
52
# File 'lib/ruby_smb/gss/provider/multi.rb', line 50

def allow_anonymous
  @providers.any?(&:allow_anonymous)
end

#allow_guests ⇒ Object



54
55
56
# File 'lib/ruby_smb/gss/provider/multi.rb', line 54

def allow_guests
  @providers.any?(&:allow_guests)
end

#mech_types ⇒ Array<OpenSSL::ASN1::ObjectId>

Every mechanism offered by every provider, in provider order, with duplicates removed so a mechanism supported by two providers is only advertised once.

Returns:

  • (Array<OpenSSL::ASN1::ObjectId>)


37
38
39
# File 'lib/ruby_smb/gss/provider/multi.rb', line 37

def mech_types
  @providers.flat_map(&:mech_types).uniq(&:oid)
end

#new_authenticator(server_client) ⇒ Object



28
29
30
# File 'lib/ruby_smb/gss/provider/multi.rb', line 28

def new_authenticator(server_client)
  Authenticator.new(self, server_client)
end

#provider_for(mech_type) ⇒ Provider::Base?

The first provider that handles the specified mechanism, or nil if none do.

Parameters:

  • mech_type (OpenSSL::ASN1::ObjectId) —

    the mechanism selected by the client

Returns:



46
47
48
# File 'lib/ruby_smb/gss/provider/multi.rb', line 46

def provider_for(mech_type)
  @providers.find { |provider| provider.supports_mech_type?(mech_type) }
end