Class: ASF::Auth::MembersAndOfficers

Inherits:
Rack::Auth::Basic
  • Object
show all
Defined in:
lib/whimsy/asf/rack.rb

Overview

Simply 'use' the following class in config.ru to limit access to the application to ASF members and officers and the EA.

Instance Method Summary collapse

Constructor Details

#initialize(app) ⇒ MembersAndOfficers

Returns a new instance of MembersAndOfficers.



22
23
24
# File 'lib/whimsy/asf/rack.rb', line 22

def initialize(app)
  super(app, "ASF Members and Officers", &proc {})
end

Instance Method Details

#call(env) ⇒ Object



26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
# File 'lib/whimsy/asf/rack.rb', line 26

def call(env)
  authorized = false

  user = env['REMOTE_USER'] ||= ENV['USER'] || Etc.getpwuid.name
  person = ASF::Person.new(user)

  authorized ||= DIRECTORS[user]
  authorized ||= person.asf_member?
  authorized ||= ASF.pmc_chairs.include? person
  authorized ||= (user == 'ea')

  if authorized
    class << env; attr_accessor :user, :password; end
    if env['HTTP_AUTHORIZATION']
      require 'base64'
      env.user, env.password = Base64.decode64(env['HTTP_AUTHORIZATION'][
        /^Basic ([A-Za-z0-9+\/=]+)$/,1]).split(':',2)
    else
      env.user = user
    end

    @app.call(env)
  else
    unauthorized
  end
end