Skip to content

Commit 720c102

Browse files
committed
[API] Adds security OIDC endpoints
1 parent 37db120 commit 720c102

File tree

6 files changed

+267
-0
lines changed

6 files changed

+267
-0
lines changed
Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
# Licensed to Elasticsearch B.V. under one or more contributor
2+
# license agreements. See the NOTICE file distributed with
3+
# this work for additional information regarding copyright
4+
# ownership. Elasticsearch B.V. licenses this file to you under
5+
# the Apache License, Version 2.0 (the "License"); you may
6+
# not use this file except in compliance with the License.
7+
# You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing,
12+
# software distributed under the License is distributed on an
13+
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14+
# KIND, either express or implied. See the License for the
15+
# specific language governing permissions and limitations
16+
# under the License.
17+
18+
module Elasticsearch
19+
module API
20+
module Security
21+
module Actions
22+
# Exchanges an OpenID Connection authentication response message for an Elasticsearch access token and refresh token pair
23+
#
24+
# @option arguments [Hash] :headers Custom HTTP headers
25+
# @option arguments [Hash] :body The OpenID Connect response to authenticate (*Required*)
26+
#
27+
# @see https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-oidc-authenticate.html
28+
#
29+
def oidc_authenticate(arguments = {})
30+
raise ArgumentError, "Required argument 'body' missing" unless arguments[:body]
31+
32+
headers = arguments.delete(:headers) || {}
33+
34+
body = arguments.delete(:body)
35+
36+
arguments = arguments.clone
37+
38+
method = Elasticsearch::API::HTTP_POST
39+
path = "_security/oidc/authenticate"
40+
params = {}
41+
42+
Elasticsearch::API::Response.new(
43+
perform_request(method, path, params, body, headers)
44+
)
45+
end
46+
end
47+
end
48+
end
49+
end
Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
# Licensed to Elasticsearch B.V. under one or more contributor
2+
# license agreements. See the NOTICE file distributed with
3+
# this work for additional information regarding copyright
4+
# ownership. Elasticsearch B.V. licenses this file to you under
5+
# the Apache License, Version 2.0 (the "License"); you may
6+
# not use this file except in compliance with the License.
7+
# You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing,
12+
# software distributed under the License is distributed on an
13+
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14+
# KIND, either express or implied. See the License for the
15+
# specific language governing permissions and limitations
16+
# under the License.
17+
18+
module Elasticsearch
19+
module API
20+
module Security
21+
module Actions
22+
# Invalidates a refresh token and access token that was generated from the OpenID Connect Authenticate API
23+
#
24+
# @option arguments [Hash] :headers Custom HTTP headers
25+
# @option arguments [Hash] :body Access token and refresh token to invalidate (*Required*)
26+
#
27+
# @see https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-oidc-logout.html
28+
#
29+
def oidc_logout(arguments = {})
30+
raise ArgumentError, "Required argument 'body' missing" unless arguments[:body]
31+
32+
headers = arguments.delete(:headers) || {}
33+
34+
body = arguments.delete(:body)
35+
36+
arguments = arguments.clone
37+
38+
method = Elasticsearch::API::HTTP_POST
39+
path = "_security/oidc/logout"
40+
params = {}
41+
42+
Elasticsearch::API::Response.new(
43+
perform_request(method, path, params, body, headers)
44+
)
45+
end
46+
end
47+
end
48+
end
49+
end
Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
# Licensed to Elasticsearch B.V. under one or more contributor
2+
# license agreements. See the NOTICE file distributed with
3+
# this work for additional information regarding copyright
4+
# ownership. Elasticsearch B.V. licenses this file to you under
5+
# the Apache License, Version 2.0 (the "License"); you may
6+
# not use this file except in compliance with the License.
7+
# You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing,
12+
# software distributed under the License is distributed on an
13+
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14+
# KIND, either express or implied. See the License for the
15+
# specific language governing permissions and limitations
16+
# under the License.
17+
18+
module Elasticsearch
19+
module API
20+
module Security
21+
module Actions
22+
# Creates an OAuth 2.0 authentication request as a URL string
23+
#
24+
# @option arguments [Hash] :headers Custom HTTP headers
25+
# @option arguments [Hash] :body The OpenID Connect authentication realm configuration (*Required*)
26+
#
27+
# @see https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-oidc-prepare-authentication.html
28+
#
29+
def oidc_prepare_authentication(arguments = {})
30+
raise ArgumentError, "Required argument 'body' missing" unless arguments[:body]
31+
32+
headers = arguments.delete(:headers) || {}
33+
34+
body = arguments.delete(:body)
35+
36+
arguments = arguments.clone
37+
38+
method = Elasticsearch::API::HTTP_POST
39+
path = "_security/oidc/prepare"
40+
params = {}
41+
42+
Elasticsearch::API::Response.new(
43+
perform_request(method, path, params, body, headers)
44+
)
45+
end
46+
end
47+
end
48+
end
49+
end
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
# Licensed to Elasticsearch B.V. under one or more contributor
2+
# license agreements. See the NOTICE file distributed with
3+
# this work for additional information regarding copyright
4+
# ownership. Elasticsearch B.V. licenses this file to you under
5+
# the Apache License, Version 2.0 (the "License"); you may
6+
# not use this file except in compliance with the License.
7+
# You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing,
12+
# software distributed under the License is distributed on an
13+
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14+
# KIND, either express or implied. See the License for the
15+
# specific language governing permissions and limitations
16+
# under the License.
17+
18+
require 'test_helper'
19+
20+
module Elasticsearch
21+
module Test
22+
class SecurityOidcAuthenticateTest < Minitest::Test
23+
context 'Security: OIDC Authenticate' do
24+
subject { FakeClient.new }
25+
26+
should 'perform correct request' do
27+
subject.expects(:perform_request).with do |method, url, params, body|
28+
assert_equal('POST', method)
29+
assert_equal('_security/oidc/authenticate', url)
30+
assert_equal({}, params)
31+
assert_equal(body, {})
32+
true
33+
end.returns(FakeResponse.new)
34+
35+
subject.security.oidc_authenticate(body: {})
36+
end
37+
end
38+
end
39+
end
40+
end
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
# Licensed to Elasticsearch B.V. under one or more contributor
2+
# license agreements. See the NOTICE file distributed with
3+
# this work for additional information regarding copyright
4+
# ownership. Elasticsearch B.V. licenses this file to you under
5+
# the Apache License, Version 2.0 (the "License"); you may
6+
# not use this file except in compliance with the License.
7+
# You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing,
12+
# software distributed under the License is distributed on an
13+
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14+
# KIND, either express or implied. See the License for the
15+
# specific language governing permissions and limitations
16+
# under the License.
17+
18+
require 'test_helper'
19+
20+
module Elasticsearch
21+
module Test
22+
class SecurityOidcLogoutTest < Minitest::Test
23+
context 'Security: OIDC Logout' do
24+
subject { FakeClient.new }
25+
26+
should 'perform correct request' do
27+
subject.expects(:perform_request).with do |method, url, params, body|
28+
assert_equal('POST', method)
29+
assert_equal('_security/oidc/logout', url)
30+
assert_equal({}, params)
31+
assert_equal(body, {})
32+
true
33+
end.returns(FakeResponse.new)
34+
35+
subject.security.oidc_logout(body: {})
36+
end
37+
end
38+
end
39+
end
40+
end
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
# Licensed to Elasticsearch B.V. under one or more contributor
2+
# license agreements. See the NOTICE file distributed with
3+
# this work for additional information regarding copyright
4+
# ownership. Elasticsearch B.V. licenses this file to you under
5+
# the Apache License, Version 2.0 (the "License"); you may
6+
# not use this file except in compliance with the License.
7+
# You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing,
12+
# software distributed under the License is distributed on an
13+
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14+
# KIND, either express or implied. See the License for the
15+
# specific language governing permissions and limitations
16+
# under the License.
17+
18+
require 'test_helper'
19+
20+
module Elasticsearch
21+
module Test
22+
class SecurityOidcPrepareAuthenticationTest < Minitest::Test
23+
context 'Security: OIDC Prepare_Authentication' do
24+
subject { FakeClient.new }
25+
26+
should 'perform correct request' do
27+
subject.expects(:perform_request).with do |method, url, params, body|
28+
assert_equal('POST', method)
29+
assert_equal('_security/oidc/prepare', url)
30+
assert_equal({}, params)
31+
assert_equal(body, {})
32+
true
33+
end.returns(FakeResponse.new)
34+
35+
subject.security.oidc_prepare_authentication(body: {})
36+
end
37+
end
38+
end
39+
end
40+
end

0 commit comments

Comments
 (0)