Class: Lockally::AdminApi
- Inherits:
-
Object
- Object
- Lockally::AdminApi
- Defined in:
- lib/lockally/api/admin_api.rb
Instance Attribute Summary collapse
-
#api_client ⇒ Object
Returns the value of attribute api_client.
Instance Method Summary collapse
-
#initialize(api_client = ApiClient.default) ⇒ AdminApi
constructor
A new instance of AdminApi.
-
#v1_admin_login_post(v1_admin_login_post_request, opts = {}) ⇒ V1AdminLoginPost200Response
Tenant-admin email+password login Exchanges an admin's email + password for a session token.
-
#v1_admin_login_post_with_http_info(v1_admin_login_post_request, opts = {}) ⇒ Array<(V1AdminLoginPost200Response, Integer, Hash)>
Tenant-admin email+password login Exchanges an admin's email + password for a session token.
-
#v1_admin_logout_post(opts = {}) ⇒ nil
Invalidate the current admin session Deletes the session row from the database.
-
#v1_admin_logout_post_with_http_info(opts = {}) ⇒ Array<(nil, Integer, Hash)>
Invalidate the current admin session Deletes the session row from the database.
-
#v1_admin_me_get(opts = {}) ⇒ V1AdminMeGet200Response
Get the current admin + tenant Returns the admin profile + tenant for the session token presented in
Authorization: Bearer. -
#v1_admin_me_get_with_http_info(opts = {}) ⇒ Array<(V1AdminMeGet200Response, Integer, Hash)>
Get the current admin + tenant Returns the admin profile + tenant for the session token presented in `Authorization: Bearer`.
Constructor Details
Instance Attribute Details
#api_client ⇒ Object
Returns the value of attribute api_client.
17 18 19 |
# File 'lib/lockally/api/admin_api.rb', line 17 def api_client @api_client end |
Instance Method Details
#v1_admin_login_post(v1_admin_login_post_request, opts = {}) ⇒ V1AdminLoginPost200Response
Tenant-admin email+password login
Exchanges an admin's email + password for a session token. The web console at app.lockally.com posts this on form submission and stores the returned token in an httpOnly cookie. No enumeration leak. Wrong-email and wrong-password both return the same 401 with title "Invalid credentials". The argon2id verify runs even on lookup miss (well, structurally — the lookup fails fast but the response shape is constant) so timing leaks are bounded. Tokens are prefixed adm_sess_ and valid for 7 days. Use as the Authorization: Bearer value on all subsequent calls.
27 28 29 30 |
# File 'lib/lockally/api/admin_api.rb', line 27 def v1_admin_login_post(v1_admin_login_post_request, opts = {}) data, _status_code, _headers = v1_admin_login_post_with_http_info(v1_admin_login_post_request, opts) data end |
#v1_admin_login_post_with_http_info(v1_admin_login_post_request, opts = {}) ⇒ Array<(V1AdminLoginPost200Response, Integer, Hash)>
Tenant-admin email+password login Exchanges an admin's email + password for a session token. The web console at `app.lockally.com` posts this on form submission and stores the returned token in an httpOnly cookie. No enumeration leak. Wrong-email and wrong-password both return the same 401 with title "Invalid credentials". The argon2id verify runs even on lookup miss (well, structurally — the lookup fails fast but the response shape is constant) so timing leaks are bounded. Tokens are prefixed `adm_sess_` and valid for 7 days. Use as the `Authorization: Bearer` value on all subsequent calls.
37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 |
# File 'lib/lockally/api/admin_api.rb', line 37 def v1_admin_login_post_with_http_info(v1_admin_login_post_request, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AdminApi.v1_admin_login_post ...' end # verify the required parameter 'v1_admin_login_post_request' is set if @api_client.config.client_side_validation && v1_admin_login_post_request.nil? fail ArgumentError, "Missing the required parameter 'v1_admin_login_post_request' when calling AdminApi.v1_admin_login_post" end # resource path local_var_path = '/v1/admin/login' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json', 'application/problem+json']) unless header_params['Accept'] # HTTP header 'Content-Type' content_type = @api_client.select_header_content_type(['application/json']) if !content_type.nil? header_params['Content-Type'] = content_type end # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] || @api_client.object_to_http_body(v1_admin_login_post_request) # return_type return_type = opts[:debug_return_type] || 'V1AdminLoginPost200Response' # auth_names auth_names = opts[:debug_auth_names] || [] = opts.merge( :operation => :"AdminApi.v1_admin_login_post", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:POST, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AdminApi#v1_admin_login_post\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#v1_admin_logout_post(opts = {}) ⇒ nil
Invalidate the current admin session Deletes the session row from the database. Idempotent — calling logout on an already-invalid token returns 204 anyway.
94 95 96 97 |
# File 'lib/lockally/api/admin_api.rb', line 94 def v1_admin_logout_post(opts = {}) v1_admin_logout_post_with_http_info(opts) nil end |
#v1_admin_logout_post_with_http_info(opts = {}) ⇒ Array<(nil, Integer, Hash)>
Invalidate the current admin session Deletes the session row from the database. Idempotent — calling logout on an already-invalid token returns 204 anyway.
103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 |
# File 'lib/lockally/api/admin_api.rb', line 103 def v1_admin_logout_post_with_http_info(opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AdminApi.v1_admin_logout_post ...' end # resource path local_var_path = '/v1/admin/logout' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/problem+json']) unless header_params['Accept'] # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] # return_type return_type = opts[:debug_return_type] # auth_names auth_names = opts[:debug_auth_names] || ['bearerAuth'] = opts.merge( :operation => :"AdminApi.v1_admin_logout_post", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:POST, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AdminApi#v1_admin_logout_post\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#v1_admin_me_get(opts = {}) ⇒ V1AdminMeGet200Response
Get the current admin + tenant
Returns the admin profile + tenant for the session token presented in Authorization: Bearer. Used by the web console's layout load function to populate the sidebar. Returns 403 if called with an API key (lk_live_*) bearer — admin context only exists for session tokens.
151 152 153 154 |
# File 'lib/lockally/api/admin_api.rb', line 151 def v1_admin_me_get(opts = {}) data, _status_code, _headers = v1_admin_me_get_with_http_info(opts) data end |
#v1_admin_me_get_with_http_info(opts = {}) ⇒ Array<(V1AdminMeGet200Response, Integer, Hash)>
Get the current admin + tenant Returns the admin profile + tenant for the session token presented in `Authorization: Bearer`. Used by the web console's layout load function to populate the sidebar. Returns 403 if called with an API key (lk_live_*) bearer — admin context only exists for session tokens.
160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 |
# File 'lib/lockally/api/admin_api.rb', line 160 def v1_admin_me_get_with_http_info(opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AdminApi.v1_admin_me_get ...' end # resource path local_var_path = '/v1/admin/me' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json', 'application/problem+json']) unless header_params['Accept'] # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] # return_type return_type = opts[:debug_return_type] || 'V1AdminMeGet200Response' # auth_names auth_names = opts[:debug_auth_names] || ['bearerAuth'] = opts.merge( :operation => :"AdminApi.v1_admin_me_get", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:GET, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AdminApi#v1_admin_me_get\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |