docbrown/app/controllers/omniauth_callbacks_controller.rb
Fernando Valverde 5342602298
Social Auth generalization refactor (#9837)
* Add gem omniauth-apple

* Integrate omniauth-apple

* Integrate callback

* Add fields

* Add tests, fix bugs and make it all work

* Show only enabled providers for the current user

* Add default profile image for Apple

* Remove localhost patch

* Bring over the changed Apple username if the user changes it

* More specs fixed

* Incorporate feedback from PR

* Fix specs

* Simplify code and fix spec

* Fix Broadcast generators to take into account the new provider

* Fix spec

* Generate a truly unique apple_username

* Fix user specs

* Add omniauth-apple-0.0.2 to vendor cache

* Fix merge conflict and spec

* Update VCR fastly sloan cassette

* Revert "Generate a truly unique apple_username"

This reverts commit 2462875575b0bbd6b3c1d56b25afcd3189671608.

* Fix user specs

* Fix specs

* Fix specs

* Hide Connect Apple button behind a feature flag

* Revert "Hide Connect Apple button behind a feature flag"

This reverts commit 105bde0373389a4eb9b6e948f60734c7e0e99cba.

* Fix line lengths

* Fix spec

* ES tag

* CSRF bypass for Apple callback

* custom user_nickname in Apple provider with small tweaks + omniauth-apple bump

* Fixes username specs

* Makes Apple users default image Users::ProfileImageGenerator

* Fallback to mascot_image_url in test environment to avoid breaking Travis

* Fixes Apple CSRF error + makes default nickname more readable

* Trigger Travis

* Removes CSRF Apple fix from Omniauth callbacks

* Removes Envfile

Co-authored-by: rhymes <rhymesete@gmail.com>
Co-authored-by: rhymes <rhymes@hey.com>
2020-08-17 20:09:44 -04:00

99 lines
3.6 KiB
Ruby

class OmniauthCallbacksController < Devise::OmniauthCallbacksController
include Devise::Controllers::Rememberable
# Each available authentication method needs a related action that will be called
# as a callback on successful redirect from the upstream OAuth provider
Authentication::Providers.available.each do |provider_name|
define_method(provider_name) do
callback_for(provider_name)
end
end
# Callback for third party failures (shared by all providers)
def failure
error = request.env["omniauth.error"]
class_name = error.present? ? error.class.name : ""
DatadogStatsClient.increment(
"omniauth.failure",
tags: [
"class:#{class_name}",
"message:#{error&.message}",
"reason:#{error.try(:error_reason)}",
"type:#{error.try(:error)}",
"uri:#{error.try(:error_uri)}",
"provider:#{request.env['omniauth.strategy'].name}",
"origin:#{request.env['omniauth.strategy.origin']}",
"params:#{request.env['omniauth.params']}",
],
)
super
end
private
def callback_for(provider)
auth_payload = request.env["omniauth.auth"]
cta_variant = request.env["omniauth.params"]["state"].to_s
@user = Authentication::Authenticator.call(
auth_payload,
current_user: current_user,
cta_variant: cta_variant,
)
if user_persisted_and_valid?
# Devise's Omniauthable does not automatically remember users
# see <https://github.com/heartcombo/devise/wiki/Omniauthable,-sign-out-action-and-rememberable>
remember_me(@user)
set_flash_message(:notice, :success, kind: provider.to_s.titleize) if is_navigational_format?
# `event: authentication` is only needed for Warden callbacks
# see <config/initializers/persistent_csrf_token_cookie.rb>
sign_in_and_redirect(@user, event: :authentication)
# NOTE: I can't find a way to test this path
# as `User` will assign a temporary username if the username already exists
# see https://github.com/thepracticaldev/dev.to/blob/27131f6f420df347a467f8e9afc84a6af2fcb13a/app/models/user.rb#L532-L555
elsif user_persisted_but_username_taken?
redirect_to "/settings?state=previous-registration"
# NOTE: I can't find a way to test this path
# as `Authentication::Authenticator.call` invokes `User.save!` which will
# raise errors for a validation error.
# In the past we had 1 path (update_user) which would have ended up
# here in case of validation errors, see:
# https://github.com/thepracticaldev/dev.to/blob/80737b540453afe8775128cb37bd379b7c09c7e8/app/services/authorization_service.rb#L77
else
# Devise will clean this data when the user is not persisted
session["devise.#{provider}_data"] = request.env["omniauth.auth"]
user_errors = @user.errors.full_messages
Honeybadger.context({
username: @user.username,
user_id: @user.id,
auth_data: request.env["omniauth.auth"],
auth_error: request.env["omniauth.error"]&.inspect,
user_errors: user_errors
})
Honeybadger.notify("Omniauth log in error")
flash[:alert] = user_errors
redirect_to new_user_registration_url
end
rescue StandardError => e
Honeybadger.notify(e)
flash[:alert] = "Log in error: #{e}"
redirect_to new_user_registration_url
end
def user_persisted_and_valid?
@user.persisted? && @user.valid?
end
def user_persisted_but_username_taken?
@user.persisted? && @user.errors_as_sentence.include?("username has already been taken")
end
end