Class: ActiveRecord::Base
- Inherits:
-
Object
- Object
- ActiveRecord::Base
- Defined in:
- lib/super_auth/active_record.rb
Direct Known Subclasses
SuperAuth::ActiveRecord::Authorization, SuperAuth::ActiveRecord::Edge, SuperAuth::ActiveRecord::Group, SuperAuth::ActiveRecord::Permission, SuperAuth::ActiveRecord::Resource, SuperAuth::ActiveRecord::Role, SuperAuth::ActiveRecord::User
Class Method Summary collapse
-
.super_auth(parent: nil, wildcard: nil) ⇒ Object
Filter this model through the ByCurrentUser scope, keyed on the class's own name.
Class Method Details
.super_auth(parent: nil, wildcard: nil) ⇒ Object
Filter this model through the ByCurrentUser scope, keyed on the class's own name. parent: names the columns through which a grant on another record reaches a row — the row's tenancy, read off the row itself — each with the types whose rows admit through it: a Hash resource_type: String|[String] or an Array of them, the shape SuperAuth::Reach normalises and SuperAuth::RLS.enable takes under the same keyword, so the same arguments produce the same map in both layers; whether the arguments agree is what RLS.current? checks. wildcard: false drops the type-level step (a row with resource_external_id NULL admitting every record of the type), which is otherwise always emitted. Omitting it keeps whatever the class already has — the default on a first declaration, the base's value on a subclass — because a subclass usually re-declares to replace its parents, and taking the keyword's default there would silently hand back the type-level step a base opted out of, against a policy built without it. Say wildcard: true to put it back. Only true and false are accepted, with the message RLS.enable gives: nil there means "drop the step" to the scope and "leave it alone" here, and a truthy string keeps it, so neither may pass silently. The reach is validated here and the table is not read: the columns are checked on the first query, so a process can boot before its migrations run. On a subclass the call replaces the parents for that subclass alone and adds no second scope.
29 30 31 32 33 34 35 36 37 |
# File 'lib/super_auth/active_record.rb', line 29 def super_auth(parent: nil, wildcard: nil) unless [true, false, nil].include?(wildcard) raise SuperAuth::Error, "wildcard: must be true or false, got #{wildcard.inspect}" end reach = SuperAuth::Reach.normalize(resource_type: name, parent: parent) include SuperAuth::ActiveRecord::ByCurrentUser unless include?(SuperAuth::ActiveRecord::ByCurrentUser) self.super_auth_reach = reach self.super_auth_wildcard = wildcard unless wildcard.nil? end |