Masks::Rails
The consumer half: a Rails engine that mounts the code flow into an application, so signing in against a masks issuer is configuration rather than a controller you write.
It loads only when Rails::Engine is already defined. Requiring
the gem from a plain Ruby process gets Masks::Client and nothing else.
Three pieces do the work:
-
Configuration — the issuer, credentials and routes, set once in an initializer and validated on boot rather than on the first request that needs them
-
Authentication —
masks_login_url, the callback, and the session the app readscurrent_actorfrom -
ProtectedResource — the other direction — checking a bearer this app was
handed, for an API rather than a browser
This engine is the client. The provider is the masks-server gem, whether it runs elsewhere or is mounted on a subdomain of this app.
Generated from client/lib by bundle exec rake reference. Its shape is the code’s; the
prose is the RDoc in the source.
Masks::Rails::Authentication
Section titled “Masks::Rails::Authentication”| Constant | Value |
|---|---|
REQUESTS |
"masks_requests".freeze |
HANDSHAKES |
"masks_handshakes".freeze |
IDENTITY |
[ "sub", "name", "preferred_username", "email", "email_verified", "tenant", "picture", Masks::Client::Claims::AVATARS, Masks::Client::Claims::ORGANIZATION, Masks::Client::Claims::ORGANIZATIONS ].freeze |
::masks_members_only!
Section titled “::masks_members_only!”::masks_members_only!(role: nil, organization: nil, **options)#authenticate_masks!
Section titled “#authenticate_masks!”#authenticate_masks!()#authorize_masks_member!
Section titled “#authorize_masks_member!”#authorize_masks_member!(*roles, organization: nil)#masks_access_token
Section titled “#masks_access_token”#masks_access_token()#masks_account
Section titled “#masks_account”#masks_account()#masks_account_url
Section titled “#masks_account_url”#masks_account_url()#masks_claims
Section titled “#masks_claims”#masks_claims()#masks_configured?
Section titled “#masks_configured?”#masks_configured?()#masks_disconnect!
Section titled “#masks_disconnect!”#masks_disconnect!()#masks_forget
Section titled “#masks_forget”#masks_forget()#masks_handshake_path
Section titled “#masks_handshake_path”#masks_handshake_path()#masks_handshakes
Section titled “#masks_handshakes”#masks_handshakes()#masks_held
Section titled “#masks_held”#masks_held()#masks_identity
Section titled “#masks_identity”#masks_identity()#masks_identity_from
Section titled “#masks_identity_from”#masks_identity_from(tokens)#masks_login_url
Section titled “#masks_login_url”#masks_login_url(return_to: nil, organization: nil)#masks_logout_url
Section titled “#masks_logout_url”#masks_logout_url(return_to: nil)#masks_organization
Section titled “#masks_organization”#masks_organization()#masks_organizations
Section titled “#masks_organizations”#masks_organizations()#masks_permits?
Section titled “#masks_permits?”#masks_permits?(scope)#masks_post_logout_redirect_uri
Section titled “#masks_post_logout_redirect_uri”#masks_post_logout_redirect_uri()#masks_reconnect!
Section titled “#masks_reconnect!”#masks_reconnect!()#masks_refresh!
Section titled “#masks_refresh!”#masks_refresh!()#masks_refreshed_identity
Section titled “#masks_refreshed_identity”#masks_refreshed_identity(tokens)#masks_registered?
Section titled “#masks_registered?”#masks_registered?()#masks_registration
Section titled “#masks_registration”#masks_registration()#masks_requests
Section titled “#masks_requests”#masks_requests()#masks_role?
Section titled “#masks_role?”#masks_role?(*roles)#masks_scopes
Section titled “#masks_scopes”#masks_scopes()#masks_session
Section titled “#masks_session”#masks_session()#masks_signed_in?
Section titled “#masks_signed_in?”#masks_signed_in?()#masks_store
Section titled “#masks_store”#masks_store(tokens, identity: nil)#masks_tenant
Section titled “#masks_tenant”#masks_tenant()#masks_tokens
Section titled “#masks_tokens”#masks_tokens()#masks_tracker
Section titled “#masks_tracker”#masks_tracker(key)Masks::Rails::Configurable
Section titled “Masks::Rails::Configurable”#masks_config
Section titled “#masks_config”#masks_config()Masks::Rails::Configuration
Section titled “Masks::Rails::Configuration”| Attribute | Access |
|---|---|
after_sign_in |
RW |
after_sign_out |
RW |
authenticate_everything |
RW |
credentials |
W |
credentials_path |
RW |
delegates |
RW |
delegation_redirect_uri |
W |
forget |
W |
issuer |
W |
logged_out |
W |
manages |
W |
name |
W |
namespace |
RW |
organization |
W |
parent_controller |
RW |
redirect_uri |
W |
resource |
RW |
resource_scopes |
RW |
scope |
RW |
session_key |
RW |
sign_out_of_issuer |
RW |
store |
W |
::new()#approved_scope
Section titled “#approved_scope”#approved_scope()#backchannel_logout_uri_for
Section titled “#backchannel_logout_uri_for”#backchannel_logout_uri_for(request)#can_forget?
Section titled “#can_forget?”#can_forget?()#client_id_for
Section titled “#client_id_for”#client_id_for(request)#client_secret_for
Section titled “#client_secret_for”#client_secret_for(request)#configured?
Section titled “#configured?”#configured?(request)#credentials_for
Section titled “#credentials_for”#credentials_for(request)#default_credentials
Section titled “#default_credentials”#default_credentials()#delegation_redirect_uri_for
Section titled “#delegation_redirect_uri_for”#delegation_redirect_uri_for(request)#forget!
Section titled “#forget!”#forget!(request)#handshake_for
Section titled “#handshake_for”#handshake_for(request)#issuer_for
Section titled “#issuer_for”#issuer_for(request)#logged_out!
Section titled “#logged_out!”#logged_out!(request, logout)#manages?
Section titled “#manages?”#manages?(request, identity = nil)#name_for
Section titled “#name_for”#name_for(request)#organization_for
Section titled “#organization_for”#organization_for(request)#redirect_uri_for
Section titled “#redirect_uri_for”#redirect_uri_for(request)#resource_for
Section titled “#resource_for”#resource_for(request)#resource_server_for
Section titled “#resource_server_for”#resource_server_for(request)#return_to_for
Section titled “#return_to_for”#return_to_for(request)#session_for
Section titled “#session_for”#session_for(request)#store!
Section titled “#store!”#store!(request, registration)Masks::Rails::Configuration::Unconfigured
Section titled “Masks::Rails::Configuration::Unconfigured”Inherits Masks::Client::Error.
Masks::Rails::Credentials
Section titled “Masks::Rails::Credentials”| Constant | Value |
|---|---|
KEYS |
%w[client_id client_secret registration_access_token registration_client_uri].freeze |
| Attribute | Access |
|---|---|
path |
R |
::new(path)#clear!
Section titled “#clear!”#clear!()#connected?
Section titled “#connected?”#connected?()#read()#write
Section titled “#write”#write(registration)Masks::Rails::Engine
Section titled “Masks::Rails::Engine”Inherits Rails::Engine.
Masks::Rails::ProtectedResource
Section titled “Masks::Rails::ProtectedResource”::masks_protect!
Section titled “::masks_protect!”::masks_protect!(**options)#masks_authenticate
Section titled “#masks_authenticate”#masks_authenticate(scope: nil, role: nil, organization: nil)#masks_authenticate!
Section titled “#masks_authenticate!”#masks_authenticate!(scope: nil, role: nil, organization: nil, **)#masks_challenge
Section titled “#masks_challenge”#masks_challenge(error)#masks_claims
Section titled “#masks_claims”#masks_claims()#masks_proof
Section titled “#masks_proof”#masks_proof()#masks_resource
Section titled “#masks_resource”#masks_resource()#masks_resource_metadata
Section titled “#masks_resource_metadata”#masks_resource_metadata()