Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion lib/rails/auth/acl/middleware.rb
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ def initialize(app, acl: nil)
end

def call(env)
raise NotAuthorizedError, "unauthorized request" unless @acl.match(env)
raise NotAuthorizedError, "unauthorized request" unless Rails::Auth.authorized?(env) || @acl.match(env)
@app.call(env)
end
end
Expand Down
29 changes: 29 additions & 0 deletions lib/rails/auth/override.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
module Rails
# Modular resource-based authentication and authorization for Rails/Rack
module Auth
# Rack environment key for marking external authorization
AUTHORIZED_ENV_KEY = "rails-auth.authorized".freeze

# Functionality allowing external middleware to override our ACL check process
module Override
# Mark a request as externally authorized. Causes ACL checks to be skipped.
#
# @param [Hash] :env Rack environment
#
def authorized!(env)
env[AUTHORIZED_ENV_KEY] = true
end

# Check whether a request has been externally authorized? Used to bypass
# ACL check.
#
# @param [Hash] :env Rack environment
#
def authorized?(env)
env.fetch(AUTHORIZED_ENV_KEY, false)
end
end

extend Override
end
end
2 changes: 2 additions & 0 deletions lib/rails/auth/rack.rb
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@

require "rails/auth/exceptions"

require "rails/auth/override"

require "rails/auth/acl"
require "rails/auth/acl/middleware"
require "rails/auth/acl/resource"
Expand Down
20 changes: 20 additions & 0 deletions spec/rails/auth/acl/middleware_spec.rb
Original file line number Diff line number Diff line change
Expand Up @@ -21,4 +21,24 @@
expect { expect(middleware.call(request)) }.to raise_error(Rails::Auth::NotAuthorizedError)
end
end

context "externally authorized requests" do
let(:authorized) { false }
let(:external_middleware) do
Class.new do
def initialize(app)
@app = app
end

def call(env)
Rails::Auth.authorized!(env)
@app.call(env)
end
end
end

it "allows externally authorized requests" do
expect(external_middleware.new(middleware).call(request)[0]).to eq 200
end
end
end