Class: ActiveSupport::SecureCompareRotator
Relationships & Source Files | |
Super Chains via Extension / Inclusion / Inheritance | |
Instance Chain:
self,
SecurityUtils
|
|
Inherits: | Object |
Defined in: | activesupport/lib/active_support/secure_compare_rotator.rb |
Overview
Secure Compare Rotator
The SecureCompareRotator
is a wrapper around SecurityUtils.secure_compare and allows you to rotate a previously defined value to a new one.
It can be used as follow:
rotator = ActiveSupport::SecureCompareRotator.new('new_production_value')
rotator.rotate('previous_production_value')
rotator.secure_compare!('previous_production_value')
One real use case example would be to rotate a basic auth credentials:
class MyController < ApplicationController
def authenticate_request
rotator = ActiveSupport::SecureCompareRotator.new('new_password')
rotator.rotate('old_password')
authenticate_or_request_with_http_basic do |username, password|
rotator.secure_compare!(password)
rescue ActiveSupport::SecureCompareRotator::InvalidMatch
false
end
end
end
Constant Summary
-
InvalidMatch =
# File 'activesupport/lib/active_support/secure_compare_rotator.rb', line 35Class.new(StandardError)
Class Method Summary
Instance Method Summary
SecurityUtils
- Included
#fixed_length_secure_compare | See additional method definition at line 11. |
#secure_compare | Secure string comparison for strings of variable length. |
Constructor Details
.new(value, on_rotation: nil) ⇒ SecureCompareRotator
# File 'activesupport/lib/active_support/secure_compare_rotator.rb', line 37
def initialize(value, on_rotation: nil) @value = value @rotate_values = [] @on_rotation = on_rotation end
Instance Method Details
#rotate(previous_value)
[ GitHub ]# File 'activesupport/lib/active_support/secure_compare_rotator.rb', line 43
def rotate(previous_value) @rotate_values << previous_value end
#secure_compare!(other_value, on_rotation: @on_rotation)
[ GitHub ]# File 'activesupport/lib/active_support/secure_compare_rotator.rb', line 47
def secure_compare!(other_value, on_rotation: @on_rotation) if secure_compare(@value, other_value) true elsif @rotate_values.any? { |value| secure_compare(value, other_value) } on_rotation&.call true else raise InvalidMatch end end