Class: Zyphr::AuthRegistrationApi
- Inherits:
-
Object
- Object
- Zyphr::AuthRegistrationApi
- Defined in:
- lib/zyphr/api/auth_registration_api.rb
Instance Attribute Summary collapse
-
#api_client ⇒ Object
Returns the value of attribute api_client.
Instance Method Summary collapse
-
#convert_anonymous_user(convert_anonymous_user_request, opts = {}) ⇒ AuthResultResponse
Convert anonymous account to a full account Upgrade the calling anonymous user to a full email+password account in place.
-
#convert_anonymous_user_with_http_info(convert_anonymous_user_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Convert anonymous account to a full account Upgrade the calling anonymous user to a full email+password account in place.
-
#initialize(api_client = ApiClient.default) ⇒ AuthRegistrationApi
constructor
A new instance of AuthRegistrationApi.
-
#register_end_user(register_request, opts = {}) ⇒ AuthResultResponse
Register a new end user Register a new end user with email and password.
-
#register_end_user_with_http_info(register_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Register a new end user Register a new end user with email and password.
-
#sign_in_anonymously(sign_in_anonymously_request, opts = {}) ⇒ AuthResultResponse
Sign in anonymously Issue an end-user identity to a device without email, password, OAuth, or any other credential.
-
#sign_in_anonymously_with_http_info(sign_in_anonymously_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Sign in anonymously Issue an end-user identity to a device without email, password, OAuth, or any other credential.
-
#sign_in_with_game_center(sign_in_with_game_center_request, opts = {}) ⇒ AuthResultResponse
Sign in with Apple Game Center Exchange an Apple Game Center identity-verification assertion for a Zyphr end-user session.
-
#sign_in_with_game_center_with_http_info(sign_in_with_game_center_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Sign in with Apple Game Center Exchange an Apple Game Center identity-verification assertion for a Zyphr end-user session.
-
#sign_in_with_google_play_games(sign_in_with_google_play_games_request, opts = {}) ⇒ AuthResultResponse
Sign in with Google Play Games Services Exchange a Google Play Games Services (GPGS) server auth code for a Zyphr end-user session.
-
#sign_in_with_google_play_games_with_http_info(sign_in_with_google_play_games_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Sign in with Google Play Games Services Exchange a Google Play Games Services (GPGS) server auth code for a Zyphr end-user session.
Constructor Details
#initialize(api_client = ApiClient.default) ⇒ AuthRegistrationApi
Returns a new instance of AuthRegistrationApi.
19 20 21 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 19 def initialize(api_client = ApiClient.default) @api_client = api_client end |
Instance Attribute Details
#api_client ⇒ Object
Returns the value of attribute api_client.
17 18 19 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 17 def api_client @api_client end |
Instance Method Details
#convert_anonymous_user(convert_anonymous_user_request, opts = {}) ⇒ AuthResultResponse
Convert anonymous account to a full account Upgrade the calling anonymous user to a full email+password account in place. The end_user.id is preserved, so customer-domain tables with foreign keys to end_users.id need no migration on conversion. All prior sessions for the user (including the anonymous token used to make this call) are revoked. A fresh token pair is returned in the response body. The conversion is the moment the user becomes billable -- MAU is tracked from this point forward.
27 28 29 30 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 27 def convert_anonymous_user(convert_anonymous_user_request, opts = {}) data, _status_code, _headers = convert_anonymous_user_with_http_info(convert_anonymous_user_request, opts) data end |
#convert_anonymous_user_with_http_info(convert_anonymous_user_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Convert anonymous account to a full account Upgrade the calling anonymous user to a full email+password account in place. The end_user.id is preserved, so customer-domain tables with foreign keys to end_users.id need no migration on conversion. All prior sessions for the user (including the anonymous token used to make this call) are revoked. A fresh token pair is returned in the response body. The conversion is the moment the user becomes billable -- MAU is tracked from this point forward.
37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 37 def convert_anonymous_user_with_http_info(convert_anonymous_user_request, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthRegistrationApi.convert_anonymous_user ...' end # verify the required parameter 'convert_anonymous_user_request' is set if @api_client.config.client_side_validation && convert_anonymous_user_request.nil? fail ArgumentError, "Missing the required parameter 'convert_anonymous_user_request' when calling AuthRegistrationApi.convert_anonymous_user" end # resource path local_var_path = '/auth/users/convert' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json']) unless header_params['Accept'] # HTTP header 'Content-Type' content_type = @api_client.select_header_content_type(['application/json']) if !content_type.nil? header_params['Content-Type'] = content_type end # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] || @api_client.object_to_http_body(convert_anonymous_user_request) # return_type return_type = opts[:debug_return_type] || 'AuthResultResponse' # auth_names auth_names = opts[:debug_auth_names] || [] = opts.merge( :operation => :"AuthRegistrationApi.convert_anonymous_user", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:POST, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthRegistrationApi#convert_anonymous_user\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#register_end_user(register_request, opts = {}) ⇒ AuthResultResponse
Register a new end user Register a new end user with email and password.
95 96 97 98 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 95 def register_end_user(register_request, opts = {}) data, _status_code, _headers = register_end_user_with_http_info(register_request, opts) data end |
#register_end_user_with_http_info(register_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Register a new end user Register a new end user with email and password.
105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 105 def register_end_user_with_http_info(register_request, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthRegistrationApi.register_end_user ...' end # verify the required parameter 'register_request' is set if @api_client.config.client_side_validation && register_request.nil? fail ArgumentError, "Missing the required parameter 'register_request' when calling AuthRegistrationApi.register_end_user" end # resource path local_var_path = '/auth/users/register' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json']) unless header_params['Accept'] # HTTP header 'Content-Type' content_type = @api_client.select_header_content_type(['application/json']) if !content_type.nil? header_params['Content-Type'] = content_type end # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] || @api_client.object_to_http_body(register_request) # return_type return_type = opts[:debug_return_type] || 'AuthResultResponse' # auth_names auth_names = opts[:debug_auth_names] || ['ApplicationSecret', 'ApplicationPublicKey'] = opts.merge( :operation => :"AuthRegistrationApi.register_end_user", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:POST, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthRegistrationApi#register_end_user\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#sign_in_anonymously(sign_in_anonymously_request, opts = {}) ⇒ AuthResultResponse
Sign in anonymously
Issue an end-user identity to a device without email, password, OAuth, or any other credential. Idempotent per (application, environment, device_id): repeated calls with the same device_id return the same user but a fresh token pair. Prior sessions for the user remain valid until natural expiry. Anonymous users do not count toward MAU quota until their first authenticated request after sign-in (excluding /v1/auth/refresh). Convert an anonymous user to a full account via POST /v1/auth/users/convert. Pass an optional organization_id to create the anonymous user directly in an organization; the returned access token then carries org_id (and orgs), matching the org-scoped register/login flow.
163 164 165 166 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 163 def sign_in_anonymously(sign_in_anonymously_request, opts = {}) data, _status_code, _headers = sign_in_anonymously_with_http_info(sign_in_anonymously_request, opts) data end |
#sign_in_anonymously_with_http_info(sign_in_anonymously_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Sign in anonymously Issue an end-user identity to a device without email, password, OAuth, or any other credential. Idempotent per (application, environment, device_id): repeated calls with the same device_id return the same user but a fresh token pair. Prior sessions for the user remain valid until natural expiry. Anonymous users do not count toward MAU quota until their first authenticated request after sign-in (excluding /v1/auth/refresh). Convert an anonymous user to a full account via POST /v1/auth/users/convert. Pass an optional `organization_id` to create the anonymous user directly in an organization; the returned access token then carries `org_id` (and `orgs`), matching the org-scoped register/login flow.
173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 173 def sign_in_anonymously_with_http_info(sign_in_anonymously_request, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthRegistrationApi.sign_in_anonymously ...' end # verify the required parameter 'sign_in_anonymously_request' is set if @api_client.config.client_side_validation && sign_in_anonymously_request.nil? fail ArgumentError, "Missing the required parameter 'sign_in_anonymously_request' when calling AuthRegistrationApi.sign_in_anonymously" end # resource path local_var_path = '/auth/users/anonymous' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json']) unless header_params['Accept'] # HTTP header 'Content-Type' content_type = @api_client.select_header_content_type(['application/json']) if !content_type.nil? header_params['Content-Type'] = content_type end # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] || @api_client.object_to_http_body(sign_in_anonymously_request) # return_type return_type = opts[:debug_return_type] || 'AuthResultResponse' # auth_names auth_names = opts[:debug_auth_names] || ['ApplicationPublicKey'] = opts.merge( :operation => :"AuthRegistrationApi.sign_in_anonymously", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:POST, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthRegistrationApi#sign_in_anonymously\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#sign_in_with_game_center(sign_in_with_game_center_request, opts = {}) ⇒ AuthResultResponse
Sign in with Apple Game Center
Exchange an Apple Game Center identity-verification assertion for a Zyphr end-user session. Zyphr independently re-verifies the assertion server-side (Apple certificate chain, RSA-SHA256 signature, timestamp freshness, single-use replay guard, and bundle-id binding) before provisioning-or-looking-up the user and minting tokens. The user is keyed on the player's teamPlayerID (the id GameKit signs the assertion over). ## Producing the assertion (Integration) The assertion is produced on-device by the iOS app — there is no server-side way to mint it. The app calls GameKit's GKLocalPlayer.fetchItems(forIdentityVerificationSignature:), which returns publicKeyURL, signature, salt, and timestamp; combine those with the local player's teamPlayerID (NOT gamePlayerID) and the app's bundle identifier and submit them here. Two integration shapes are supported: - client-direct — the iOS app holds the Zyphr application public key and calls this endpoint itself. - backend-relayed — the app forwards the fetched assertion fields to the customer's own backend, which relays them to this endpoint; the app never holds Zyphr keys. (This is the common shape for games.) On any verification failure the response is a single opaque 401 invalid_assertion — the specific control that failed is never disclosed.
231 232 233 234 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 231 def sign_in_with_game_center(sign_in_with_game_center_request, opts = {}) data, _status_code, _headers = sign_in_with_game_center_with_http_info(sign_in_with_game_center_request, opts) data end |
#sign_in_with_game_center_with_http_info(sign_in_with_game_center_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Sign in with Apple Game Center Exchange an Apple Game Center identity-verification assertion for a Zyphr end-user session. Zyphr independently re-verifies the assertion server-side (Apple certificate chain, RSA-SHA256 signature, timestamp freshness, single-use replay guard, and bundle-id binding) before provisioning-or-looking-up the user and minting tokens. The user is keyed on the player's `teamPlayerID` (the id GameKit signs the assertion over). ## Producing the assertion (Integration) The assertion is produced on-device by the iOS app — there is no server-side way to mint it. The app calls GameKit's `GKLocalPlayer.fetchItems(forIdentityVerificationSignature:)`, which returns `publicKeyURL`, `signature`, `salt`, and `timestamp`; combine those with the local player's `teamPlayerID` (NOT `gamePlayerID`) and the app's bundle identifier and submit them here. Two integration shapes are supported: - client-direct — the iOS app holds the Zyphr application public key and calls this endpoint itself. - backend-relayed — the app forwards the fetched assertion fields to the customer's own backend, which relays them to this endpoint; the app never holds Zyphr keys. (This is the common shape for games.) On any verification failure the response is a single opaque `401` `invalid_assertion` — the specific control that failed is never disclosed.
241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 241 def sign_in_with_game_center_with_http_info(sign_in_with_game_center_request, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthRegistrationApi.sign_in_with_game_center ...' end # verify the required parameter 'sign_in_with_game_center_request' is set if @api_client.config.client_side_validation && sign_in_with_game_center_request.nil? fail ArgumentError, "Missing the required parameter 'sign_in_with_game_center_request' when calling AuthRegistrationApi.sign_in_with_game_center" end # resource path local_var_path = '/auth/game-center' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json']) unless header_params['Accept'] # HTTP header 'Content-Type' content_type = @api_client.select_header_content_type(['application/json']) if !content_type.nil? header_params['Content-Type'] = content_type end # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] || @api_client.object_to_http_body(sign_in_with_game_center_request) # return_type return_type = opts[:debug_return_type] || 'AuthResultResponse' # auth_names auth_names = opts[:debug_auth_names] || ['ApplicationPublicKey'] = opts.merge( :operation => :"AuthRegistrationApi.sign_in_with_game_center", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:POST, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthRegistrationApi#sign_in_with_game_center\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#sign_in_with_google_play_games(sign_in_with_google_play_games_request, opts = {}) ⇒ AuthResultResponse
Sign in with Google Play Games Services
Exchange a Google Play Games Services (GPGS) server auth code for a Zyphr end-user session. Unlike Game Center (which submits an Apple-signed assertion), GPGS is verified by Google: Zyphr exchanges the single-use server auth code at Google's OAuth2 token endpoint, then calls the Play Games REST API (players/me) server-side to obtain the trusted, tamper-proof playerId. The user is provisioned-or-looked-up on that server-fetched playerId and tokens are minted. ## Producing the server auth code (Integration) The server auth code is obtained on-device by the Android app — there is no server-side way to mint it. The app calls GamesSignInClient.requestServerSideAccess(serverClientId, …) using the Google Cloud web (server) client id configured for the game, which returns a single-use auth code string. Submit that string here as serverAuthCode. The backend-relayed shape is the common one: the app forwards the auth code to the customer's own backend, which relays it to this endpoint; the app never holds Zyphr keys. ## Security The playerId is derived only from Zyphr's own server-side call to Google after the token exchange — a client-supplied player id is never accepted or trusted. On any verification failure the response is a single opaque 401 invalid_auth_code; the specific control that failed is never disclosed.
299 300 301 302 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 299 def sign_in_with_google_play_games(sign_in_with_google_play_games_request, opts = {}) data, _status_code, _headers = sign_in_with_google_play_games_with_http_info(sign_in_with_google_play_games_request, opts) data end |
#sign_in_with_google_play_games_with_http_info(sign_in_with_google_play_games_request, opts = {}) ⇒ Array<(AuthResultResponse, Integer, Hash)>
Sign in with Google Play Games Services Exchange a Google Play Games Services (GPGS) server auth code for a Zyphr end-user session. Unlike Game Center (which submits an Apple-signed assertion), GPGS is verified by Google: Zyphr exchanges the single-use server auth code at Google's OAuth2 token endpoint, then calls the Play Games REST API (`players/me`) server-side to obtain the trusted, tamper-proof `playerId`. The user is provisioned-or-looked-up on that server-fetched `playerId` and tokens are minted. ## Producing the server auth code (Integration) The server auth code is obtained on-device by the Android app — there is no server-side way to mint it. The app calls `GamesSignInClient.requestServerSideAccess(serverClientId, …)` using the Google Cloud web (server) client id configured for the game, which returns a single-use auth code string. Submit that string here as `serverAuthCode`. The backend-relayed shape is the common one: the app forwards the auth code to the customer's own backend, which relays it to this endpoint; the app never holds Zyphr keys. ## Security The `playerId` is derived only from Zyphr's own server-side call to Google after the token exchange — a client-supplied player id is never accepted or trusted. On any verification failure the response is a single opaque `401` `invalid_auth_code`; the specific control that failed is never disclosed.
309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 |
# File 'lib/zyphr/api/auth_registration_api.rb', line 309 def sign_in_with_google_play_games_with_http_info(sign_in_with_google_play_games_request, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthRegistrationApi.sign_in_with_google_play_games ...' end # verify the required parameter 'sign_in_with_google_play_games_request' is set if @api_client.config.client_side_validation && sign_in_with_google_play_games_request.nil? fail ArgumentError, "Missing the required parameter 'sign_in_with_google_play_games_request' when calling AuthRegistrationApi.sign_in_with_google_play_games" end # resource path local_var_path = '/auth/google-play-games' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json']) unless header_params['Accept'] # HTTP header 'Content-Type' content_type = @api_client.select_header_content_type(['application/json']) if !content_type.nil? header_params['Content-Type'] = content_type end # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] || @api_client.object_to_http_body(sign_in_with_google_play_games_request) # return_type return_type = opts[:debug_return_type] || 'AuthResultResponse' # auth_names auth_names = opts[:debug_auth_names] || ['ApplicationPublicKey'] = opts.merge( :operation => :"AuthRegistrationApi.sign_in_with_google_play_games", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:POST, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthRegistrationApi#sign_in_with_google_play_games\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |