Skip to content

Masks::Rails

The consumer half: a Rails engine that mounts the code flow into an application, so signing in against a masks issuer is configuration rather than a controller you write.

It loads only when Rails::Engine is already defined. Requiring the gem from a plain Ruby process gets Masks::Client and nothing else.

Three pieces do the work:

  • Configuration — the issuer, credentials and routes, set once in an initializer and validated on boot rather than on the first request that needs them

  • Authentication — masks_login_url, the callback, and the session the app reads current_actor from

  • ProtectedResource — the other direction — checking a bearer this app was

    handed, for an API rather than a browser

This engine is the client. The provider is the masks-server gem, whether it runs elsewhere or is mounted on a subdomain of this app.

Generated from client/lib by bundle exec rake reference. Its shape is the code’s; the prose is the RDoc in the source.

Constant Value
REQUESTS "masks_requests".freeze
HANDSHAKES "masks_handshakes".freeze
IDENTITY [ "sub", "name", "preferred_username", "email", "email_verified", "tenant", "picture", Masks::Client::Claims::AVATARS, Masks::Client::Claims::ORGANIZATION, Masks::Client::Claims::ORGANIZATIONS ].freeze
::masks_members_only!(role: nil, organization: nil, **options)
#authenticate_masks!()
#authorize_masks_member!(*roles, organization: nil)
#masks_access_token()
#masks_account()
#masks_account_url()
#masks_claims()
#masks_configured?()
#masks_disconnect!()
#masks_forget()
#masks_handshake_path()
#masks_handshakes()
#masks_held()
#masks_identity()
#masks_identity_from(tokens)
#masks_login_url(return_to: nil, organization: nil)
#masks_logout_url(return_to: nil)
#masks_organization()
#masks_organizations()
#masks_permits?(scope)
#masks_post_logout_redirect_uri()
#masks_reconnect!()
#masks_refresh!()
#masks_refreshed_identity(tokens)
#masks_registered?()
#masks_registration()
#masks_requests()
#masks_role?(*roles)
#masks_scopes()
#masks_session()
#masks_signed_in?()
#masks_store(tokens, identity: nil)
#masks_tenant()
#masks_tokens()
#masks_tracker(key)
#masks_config()
Attribute Access
after_sign_in RW
after_sign_out RW
authenticate_everything RW
credentials W
credentials_path RW
delegates RW
delegation_redirect_uri W
forget W
issuer W
logged_out W
manages W
name W
namespace RW
organization W
parent_controller RW
redirect_uri W
resource RW
resource_scopes RW
scope RW
session_key RW
sign_out_of_issuer RW
store W
::new()
#approved_scope()
#backchannel_logout_uri_for(request)
#can_forget?()
#client_id_for(request)
#client_secret_for(request)
#configured?(request)
#credentials_for(request)
#default_credentials()
#delegation_redirect_uri_for(request)
#forget!(request)
#handshake_for(request)
#issuer_for(request)
#logged_out!(request, logout)
#manages?(request, identity = nil)
#name_for(request)
#organization_for(request)
#redirect_uri_for(request)
#resource_for(request)
#resource_server_for(request)
#return_to_for(request)
#session_for(request)
#store!(request, registration)

Inherits Masks::Client::Error.

Constant Value
KEYS %w[client_id client_secret registration_access_token registration_client_uri].freeze
Attribute Access
path R
::new(path)
#clear!()
#connected?()
#read()
#write(registration)

Inherits Rails::Engine.

::masks_protect!(**options)
#masks_authenticate(scope: nil, role: nil, organization: nil)
#masks_authenticate!(scope: nil, role: nil, organization: nil, **)
#masks_challenge(error)
#masks_claims()
#masks_proof()
#masks_resource()
#masks_resource_metadata()