|
| 1 | +require "digest" |
| 2 | + |
| 3 | +class ApiCredential < ApplicationRecord |
| 4 | + belongs_to :user |
| 5 | + |
| 6 | + before_save :generate_api_token |
| 7 | + before_save :generate_refresh_token |
| 8 | + |
| 9 | + # Securely confirm/deny that Hash in db is same as current users token Hash |
| 10 | + def authenticate_api_token(api_token) |
| 11 | + Digest::SHA256.hexdigest(api_token) == api_token_digest |
| 12 | + end |
| 13 | + |
| 14 | + def authenticate_refresh_token(refresh_token) |
| 15 | + Digest::SHA256.hexdigest(refresh_token) == refresh_token_digest |
| 16 | + end |
| 17 | + |
| 18 | + # Securely generate and then return new tokens |
| 19 | + def return_new_api_token! |
| 20 | + new_token = generate_api_token |
| 21 | + update_column(:api_token_digest, api_token_digest) |
| 22 | + {api_token: new_token} |
| 23 | + end |
| 24 | + |
| 25 | + def return_new_refresh_token! |
| 26 | + new_token = generate_refresh_token |
| 27 | + update_column(:refresh_token_digest, refresh_token_digest) |
| 28 | + {refresh_token: new_token} |
| 29 | + end |
| 30 | + |
| 31 | + # Verifying token has or has not expired |
| 32 | + def is_api_token_expired? |
| 33 | + token_expires_at < Time.current |
| 34 | + end |
| 35 | + |
| 36 | + def is_refresh_token_expired? |
| 37 | + refresh_token_expires_at < Time.current |
| 38 | + end |
| 39 | + |
| 40 | + private |
| 41 | + |
| 42 | + # Generate unique tokens and hashes them for secure db storage |
| 43 | + def generate_api_token |
| 44 | + new_api_token = SecureRandom.hex(18) |
| 45 | + self.api_token_digest = Digest::SHA256.hexdigest(new_api_token) |
| 46 | + new_api_token |
| 47 | + end |
| 48 | + |
| 49 | + def generate_refresh_token |
| 50 | + new_refresh_token = SecureRandom.hex(18) |
| 51 | + self.refresh_token_digest = Digest::SHA256.hexdigest(new_refresh_token) |
| 52 | + new_refresh_token |
| 53 | + end |
| 54 | +end |
| 55 | + |
| 56 | +# == Schema Information |
| 57 | +# |
| 58 | +# Table name: api_credentials |
| 59 | +# |
| 60 | +# id :bigint not null, primary key |
| 61 | +# api_token_digest :string |
| 62 | +# refresh_token_digest :string |
| 63 | +# refresh_token_expires_at :datetime |
| 64 | +# token_expires_at :datetime |
| 65 | +# created_at :datetime not null |
| 66 | +# updated_at :datetime not null |
| 67 | +# user_id :bigint not null |
| 68 | +# |
| 69 | +# Indexes |
| 70 | +# |
| 71 | +# index_api_credentials_on_api_token_digest (api_token_digest) UNIQUE WHERE (api_token_digest IS NOT NULL) |
| 72 | +# index_api_credentials_on_refresh_token_digest (refresh_token_digest) UNIQUE WHERE (refresh_token_digest IS NOT NULL) |
| 73 | +# index_api_credentials_on_user_id (user_id) |
| 74 | +# |
| 75 | +# Foreign Keys |
| 76 | +# |
| 77 | +# fk_rails_... (user_id => users.id) |
| 78 | +# |
0 commit comments