Module: Doorkeeper::AccessTokenMixin
- Extended by:
- ActiveSupport::Concern
- Includes:
- Models::Accessible, Models::Concerns::WriteToPrimary, Models::Expirable, Models::ExpirationTimeSqlMath, Models::Orderable, Models::ResourceOwnerable, Models::Reusable, Models::Revocable, Models::Scopes, Models::SecretStorable, OAuth::Helpers
- Defined in:
- lib/doorkeeper/models/access_token_mixin.rb
Defined Under Namespace
Modules: ClassMethods
Constant Summary
Constants included from Models::ExpirationTimeSqlMath
Models::ExpirationTimeSqlMath::ADAPTERS_MAPPING, Models::ExpirationTimeSqlMath::WARNING_MESSAGE
Instance Method Summary collapse
-
#acceptable?(scopes) ⇒ Boolean
Indicates if token is acceptable for specific scopes.
-
#as_json(_options = {}) ⇒ Hash
JSON representation of the Access Token instance.
-
#custom_attributes ⇒ Hash
The token's custom attributes, as defined by the custom_access_token_attributes config option.
-
#plaintext_refresh_token ⇒ Object
We keep a volatile copy of the raw refresh token for initial communication The stored refresh_token may be mapped and not available in cleartext.
-
#plaintext_token ⇒ Object
We keep a volatile copy of the raw token for initial communication The stored refresh_token may be mapped and not available in cleartext.
-
#revoke_previous_refresh_token! ⇒ Object
Revokes token with
:refresh_tokenequal to:previous_refresh_tokenand clears:previous_refresh_tokenattribute. -
#same_credential?(access_token) ⇒ Boolean
Indicates whether the token instance have the same credential as the other Access Token.
-
#same_resource_owner?(access_token) ⇒ Boolean
Indicates whether the token instance have the same credential as the other Access Token.
-
#token_type ⇒ Object
Access Token type: Bearer.
- #use_refresh_token? ⇒ Boolean
Methods included from Models::Scopes
#includes_scope?, #scopes, #scopes=, #scopes_string
Methods included from Models::Accessible
Methods included from Models::Revocable
Methods included from Models::Reusable
Methods included from Models::Expirable
#expired?, #expires_at, #expires_in_seconds
Instance Method Details
#acceptable?(scopes) ⇒ Boolean
Indicates if token is acceptable for specific scopes.
491 492 493 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 491 def acceptable?(scopes) accessible? && includes_scope?(*scopes) end |
#as_json(_options = {}) ⇒ Hash
JSON representation of the Access Token instance.
435 436 437 438 439 440 441 442 443 444 445 446 447 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 435 def as_json( = {}) { resource_owner_id: resource_owner_id, scope: scopes, expires_in: expires_in_seconds, application: { uid: application.try(:uid) }, created_at: created_at.to_i, }.tap do |json| if Doorkeeper.configuration.polymorphic_resource_owner? json[:resource_owner_type] = resource_owner_type end end end |
#custom_attributes ⇒ Hash
The token's custom attributes, as defined by the custom_access_token_attributes config option.
453 454 455 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 453 def custom_attributes self.class.extract_custom_attributes(attributes) end |
#plaintext_refresh_token ⇒ Object
We keep a volatile copy of the raw refresh token for initial communication The stored refresh_token may be mapped and not available in cleartext.
497 498 499 500 501 502 503 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 497 def plaintext_refresh_token if secret_strategy.allows_restoring_secrets? secret_strategy.restore_secret(self, :refresh_token) else @raw_refresh_token end end |
#plaintext_token ⇒ Object
We keep a volatile copy of the raw token for initial communication The stored refresh_token may be mapped and not available in cleartext.
Some strategies allow restoring stored secrets (e.g. symmetric encryption) while hashing strategies do not, so you cannot rely on this value returning a present value for persisted tokens.
511 512 513 514 515 516 517 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 511 def plaintext_token if secret_strategy.allows_restoring_secrets? secret_strategy.restore_secret(self, :token) else @raw_token end end |
#revoke_previous_refresh_token! ⇒ Object
Revokes token with :refresh_token equal to :previous_refresh_token
and clears :previous_refresh_token attribute.
522 523 524 525 526 527 528 529 530 531 532 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 522 def revoke_previous_refresh_token! return if !self.class.refresh_token_revoked_on_use? || previous_refresh_token.blank? old_refresh_token&.revoke if self.class.respond_to?(:with_primary_role) self.class.with_primary_role { update_attribute(:previous_refresh_token, "") } else update_attribute(:previous_refresh_token, "") end end |
#same_credential?(access_token) ⇒ Boolean
Indicates whether the token instance have the same credential as the other Access Token.
464 465 466 467 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 464 def same_credential?(access_token) application_id == access_token.application_id && same_resource_owner?(access_token) end |
#same_resource_owner?(access_token) ⇒ Boolean
Indicates whether the token instance have the same credential as the other Access Token.
476 477 478 479 480 481 482 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 476 def same_resource_owner?(access_token) if Doorkeeper.configuration.polymorphic_resource_owner? resource_owner == access_token.resource_owner else resource_owner_id == access_token.resource_owner_id end end |
#token_type ⇒ Object
Access Token type: Bearer.
423 424 425 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 423 def token_type "Bearer" end |
#use_refresh_token? ⇒ Boolean
427 428 429 430 |
# File 'lib/doorkeeper/models/access_token_mixin.rb', line 427 def use_refresh_token? @use_refresh_token ||= false !!@use_refresh_token end |