class Mongo::Auth::X509::Conversation

Defines behavior around a single x.509 conversation between the client and server.

@since 2.0.0

Constants

LOGIN

The login message.

@since 2.0.0

Attributes

reply[R]

@return [ Protocol::Message ] reply The current reply in the

conversation.
user[R]

@return [ User ] user The user for the conversation.

Public Class Methods

new(user) click to toggle source

Create the new conversation.

@example Create the new conversation.

Conversation.new(user, "admin")

@param [ Auth::User ] user The user to converse about.

@since 2.0.0

# File lib/mongo/auth/x509/conversation.rb, line 91
def initialize(user)
  @user = user
end

Public Instance Methods

finalize(reply) click to toggle source

Finalize the x.509 conversation. This is meant to be iterated until the provided reply indicates the conversation is finished.

@example Finalize the conversation.

conversation.finalize(reply)

@param [ Protocol::Message ] reply The reply of the previous

message.

@return [ Protocol::Query ] The next message to send.

@since 2.0.0

# File lib/mongo/auth/x509/conversation.rb, line 49
def finalize(reply)
  validate!(reply)
end
start(connection = nil) click to toggle source

Start the x.509 conversation. This returns the first message that needs to be sent to the server.

@example Start the conversation.

conversation.start

@param [ Mongo::Server::Connection ] connection The connection being authenticated.

@return [ Protocol::Query ] The first x.509 conversation message.

@since 2.0.0

# File lib/mongo/auth/x509/conversation.rb, line 64
def start(connection = nil)
  login = LOGIN.merge(mechanism: X509::MECHANISM)
  login[:user] = user.name if user.name
  if connection && connection.features.op_msg_enabled?
    selector = login
    selector[Protocol::Msg::DATABASE_IDENTIFIER] = user.auth_source
    cluster_time = connection.mongos? && connection.cluster_time
    selector[Operation::CLUSTER_TIME] = cluster_time if cluster_time
    Protocol::Msg.new([], {}, selector)
  else
    Protocol::Query.new(
      Auth::EXTERNAL,
      Database::COMMAND,
      login,
      limit: -1
    )
  end
end

Private Instance Methods

validate!(reply) click to toggle source
# File lib/mongo/auth/x509/conversation.rb, line 97
def validate!(reply)
  if reply.documents[0][Operation::Result::OK] != 1
    raise Unauthorized.new(user, MECHANISM)
  end
  @reply = reply
end