Class: Wurk::API::Request
- Inherits:
-
Rack::Request
- Object
- Rack::Request
- Wurk::API::Request
- Defined in:
- lib/wurk/api/request.rb
Overview
Rack::Request plus the three things every API handler needs: the segment
captures the router bound ('/jobs/:jid' → path_params[:jid]), the
authenticated principal, and mount-agnostic URL building.
Instance Attribute Summary collapse
-
#config ⇒ Object
The configuration this app is answering from, stamped by App before anything reads it.
- #path_params ⇒ Object
-
#principal ⇒ Object
Set by App once Auth has accepted the credential, so a handler can ask what the caller was granted without re-reading the header.
Instance Method Summary collapse
-
#read_body(limit) ⇒ Object
At most
limitbytes off the request body, so a caller can refuse an oversized one without ever holding it. -
#url_for(path) ⇒ Object
Root-relative on purpose.
Instance Attribute Details
#config ⇒ Object
The configuration this app is answering from, stamped by App before anything reads it. Injectable there for tests, so a handler that wants a boundary cap or a token's grants must ask the request rather than reaching for the process-wide singleton behind the app's back.
20 21 22 |
# File 'lib/wurk/api/request.rb', line 20 def config @config end |
#path_params ⇒ Object
24 25 26 |
# File 'lib/wurk/api/request.rb', line 24 def path_params @path_params ||= {} end |
#principal ⇒ Object
Set by App once Auth has accepted the credential, so a handler can ask what the caller was granted without re-reading the header. Never nil by the time a handler runs — an unauthenticated request never reaches one.
14 15 16 |
# File 'lib/wurk/api/request.rb', line 14 def principal @principal end |
Instance Method Details
#read_body(limit) ⇒ Object
At most limit bytes off the request body, so a caller can refuse an
oversized one without ever holding it. Rack 3.1 made rack.input
optional and a stream already at EOF answers nil, so both come back as
an empty string: a bodyless request is a request, not a crash.
41 42 43 |
# File 'lib/wurk/api/request.rb', line 41 def read_body(limit) body&.read(limit).to_s end |
#url_for(path) ⇒ Object
Root-relative on purpose. The API answers under three different prefixes (engine-nested, separately mounted, standalone) and usually sits behind a proxy, so SCRIPT_NAME is the only prefix it can trust — rebuilding an absolute URL out of Host/X-Forwarded-* would hand clients links to an origin they never asked for.
33 34 35 |
# File 'lib/wurk/api/request.rb', line 33 def url_for(path) "#{script_name.to_s.chomp('/')}#{path}" end |