Class: ActiveSupport::SecureCompareRotator
- Includes:
 - Messages::Rotator, SecurityUtils
 
- Defined in:
 - lib/active_support/secure_compare_rotator.rb
 
Overview
The ActiveSupport::SecureCompareRotator is a wrapper around ActiveSupport::SecurityUtils.secure_compare and allows you to rotate a previously defined value to a new one.
It can be used as follow:
rotator = ActiveSupport::SecureCompareRotator.new('new_production_value')
rotator.rotate('previous_production_value')
rotator.secure_compare!('previous_production_value')
One real use case example would be to rotate a basic auth credentials:
class MyController < ApplicationController
  def authenticate_request
    rotator = ActiveSupport::SecureCompareRotator.new('new_password')
    rotator.rotate('old_password')
    authenticate_or_request_with_http_basic do |username, password|
      rotator.secure_compare!(password)
    rescue ActiveSupport::SecureCompareRotator::InvalidMatch
      false
    end
  end
end
  Constant Summary collapse
- InvalidMatch =
 Class.new(StandardError)
Instance Method Summary collapse
- 
  
    
      #initialize(value, **_options)  ⇒ SecureCompareRotator 
    
    
  
  
  
    constructor
  
  
  
  
  
  
  
    
A new instance of SecureCompareRotator.
 - #secure_compare!(other_value, on_rotation: @on_rotation) ⇒ Object
 
Methods included from SecurityUtils
fixed_length_secure_compare, secure_compare
Methods included from Messages::Rotator
Constructor Details
#initialize(value, **_options) ⇒ SecureCompareRotator
Returns a new instance of SecureCompareRotator.
      36 37 38  | 
    
      # File 'lib/active_support/secure_compare_rotator.rb', line 36 def initialize(value, **) @value = value end  | 
  
Instance Method Details
#secure_compare!(other_value, on_rotation: @on_rotation) ⇒ Object
      40 41 42 43 44  | 
    
      # File 'lib/active_support/secure_compare_rotator.rb', line 40 def secure_compare!(other_value, on_rotation: @on_rotation) secure_compare(@value, other_value) || run_rotations(on_rotation) { |wrapper| wrapper.secure_compare!(other_value) } || raise(InvalidMatch) end  |