Module: Yes::Core::Authorization::CerbosClientProvider

Included in:
CommandCerbosAuthorizer, ReadRequestCerbosAuthorizer
Defined in:
lib/yes/core/authorization/cerbos_client_provider.rb

Overview

Provides a shared Cerbos client instance for authorizer classes.

One client (and therefore one gRPC channel) is kept per process. Cerbos::Client is thread-safe, but a gRPC channel must not be shared across a fork, so the client is rebuilt in each forked worker.

Examples:

Including in a class with class-level methods

class MyAuthorizer
  class << self
    include Yes::Core::Authorization::CerbosClientProvider
  end
end

Class Method Summary collapse

Class Method Details

.client ⇒ Cerbos::Client

Returns the process-wide Cerbos client.

Returns:

  • (Cerbos::Client) —

    the process-wide Cerbos client



21
22
23
24
25
26
# File 'lib/yes/core/authorization/cerbos_client_provider.rb', line 21

def client
  mutex.synchronize do
    reset! unless @client_pid == Process.pid
    @client ||= build_client
  end
end

.reset! ⇒ void

This method returns an undefined value.

Drops the memoized client so the next call builds a new one (used after a fork and in tests).



31
32
33
34
# File 'lib/yes/core/authorization/cerbos_client_provider.rb', line 31

def reset!
  @client = nil
  @client_pid = Process.pid
end