Sha256: 2ae539aca39e206d6265144b8da7ae32ad020f0a86d33655dd08a97fdd11a987

Contents?: true

Size: 1.85 KB

Versions: 6

Compression:

Stored size: 1.85 KB

Contents

module GDS
  module SSO
    module ControllerMethods
      class PermissionDeniedException < StandardError
      end

      def self.included(base)
        base.rescue_from PermissionDeniedException do |e|
          render "authorisations/unauthorised", layout: "unauthorised", status: :forbidden, locals: { message: e.message }
        end
        base.helper_method :user_signed_in?
        base.helper_method :current_user
      end


      def authorise_user!(scope, permission)
        # Ensure that we're authenticated (and by extension that current_user is set).
        # Otherwise current_user might be nil, and we'd error out
        authenticate_user!

        if not current_user.has_permission?(scope, permission)
          raise PermissionDeniedException, "Sorry, you don't seem to have the #{permission} permission for #{scope}."
        end
      end

      def require_signin_permission!
        authorise_user!(GDS::SSO::Config.default_scope, 'signin')
      rescue PermissionDeniedException
        skip_slimmer
        render "authorisations/cant_signin", layout: "unauthorised", status: :forbidden
      end

      def authenticate_user!
        if current_user && current_user.remotely_signed_out?
          message = "You have been remotely signed out."
          skip_slimmer
          render "authorisations/unauthorised", layout: "unauthorised", status: :forbidden, locals: { message: message }
        end
        warden.authenticate!
      end

      def user_signed_in?
        warden.authenticated?
      end

      def current_user
        warden.user if user_signed_in?
      end

      def log_out
        warden.log_out
      end

      def warden
        request.env['warden']
      end

      def skip_slimmer
        # If slimmer used, without this you would see a generic 400 error page
        headers["X-Slimmer-Skip"] = "1"
      end
    end
  end
end

Version data entries

6 entries across 6 versions & 1 rubygems

Version Path
gds-sso-2.0.1 lib/gds-sso/controller_methods.rb
gds-sso-2.0.0 lib/gds-sso/controller_methods.rb
gds-sso-1.2.2 lib/gds-sso/controller_methods.rb
gds-sso-1.2.1 lib/gds-sso/controller_methods.rb
gds-sso-1.2.0 lib/gds-sso/controller_methods.rb
gds-sso-1.1.1 lib/gds-sso/controller_methods.rb