Class: CommandTower::Services::Auth::AuthorizeRequest

Inherits:
CommandTower::Services::ApplicationService show all
Defined in:
app/services/command_tower/services/auth/authorize_request.rb

Constant Summary

Constants inherited from CommandTower::ServiceBase

CommandTower::ServiceBase::ON_ARGUMENT_VALIDATION

Instance Method Summary collapse

Methods inherited from CommandTower::Services::ApplicationService

call, inherited

Methods included from Transactional

#fail_transaction!, #transaction

Methods inherited from CommandTower::ServiceBase

#command_tower_lifecycle, inherited, #internal_validate, #service_lifecycle_error_codes, #service_lifecycle_log_level, #validate!

Methods included from Logging::LifecycleDeclaration

included

Methods included from Execution::ContextAccess

#audit, #execution_context, #log_debug, #log_error, #log_info, #log_warn, #publish_event

Methods included from ArgumentValidation

included

Methods included from CommandTower::ServiceLogging

included

Instance Method Details

#callObject



11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
# File 'app/services/command_tower/services/auth/authorize_request.rb', line 11

def call
  result = CommandTower::Authorize::Validate.call(
    user: current_user,
    controller: controller_class,
    method: action_name
  )

  context.authorization_required = result.authorization_required

  if result.failure?
    context.fail!(application_error: CommandTower::Errors::ForbiddenError.new)
    return
  end

  # Fail closed: an action the host never mapped into RBAC is not
  # implicitly public once it sits behind the authorization boundary.
  unless result.authorization_required
    context.fail!(application_error: CommandTower::Errors::ForbiddenError.new)
  end
end