class Rack::Protection::Base

Constants

DEFAULT_OPTIONS

Attributes

app[R]
options[R]

Public Class Methods

default_options(options) click to toggle source
Calls superclass method
# File lib/rack/protection/base.rb, line 19
def self.default_options(options)
  define_method(:default_options) { super().merge(options) }
end
default_reaction(reaction) click to toggle source
# File lib/rack/protection/base.rb, line 23
def self.default_reaction(reaction)
  alias_method(:default_reaction, reaction)
end
new(app, options = {}) click to toggle source
# File lib/rack/protection/base.rb, line 31
def initialize(app, options = {})
  @app, @options = app, default_options.merge(options)
end

Public Instance Methods

accepts?(env) click to toggle source
# File lib/rack/protection/base.rb, line 39
def accepts?(env)
  raise NotImplementedError, "#{self.class} implementation pending"
end
call(env) click to toggle source
# File lib/rack/protection/base.rb, line 43
def call(env)
  unless accepts? env
    warn env, "attack prevented by #{self.class}"
    result = react env
  end
  result or app.call(env)
end
default_options() click to toggle source
# File lib/rack/protection/base.rb, line 27
def default_options
  DEFAULT_OPTIONS
end
default_reaction(env)
Alias for: deny
deny(env) click to toggle source
# File lib/rack/protection/base.rb, line 62
def deny(env)
  [options[:status], {'Content-Type' => 'text/plain'}, [options[:message]]]
end
Also aliased as: default_reaction
drop_session(env) click to toggle source
# File lib/rack/protection/base.rb, line 75
def drop_session(env)
  session(env).clear if session? env
end
encrypt(value) click to toggle source
# File lib/rack/protection/base.rb, line 95
def encrypt(value)
  options[:encryptor].hexdigest value.to_s
end
html?(headers) click to toggle source
# File lib/rack/protection/base.rb, line 101
def html?(headers)
  return false unless header = headers.detect { |k,v| k.downcase == 'content-type' }
  options[:html_types].include? header.last[/^\w+\/\w+/]
end
origin(env) click to toggle source
# File lib/rack/protection/base.rb, line 85
def origin(env)
  env['HTTP_ORIGIN'] || env['HTTP_X_ORIGIN']
end
random_string(secure = defined? SecureRandom) click to toggle source
# File lib/rack/protection/base.rb, line 89
def random_string(secure = defined? SecureRandom)
  secure ? SecureRandom.hex(32) : "%032x" % rand(2**128-1)
rescue NotImplementedError
  random_string false
end
react(env) click to toggle source
# File lib/rack/protection/base.rb, line 51
def react(env)
  result = send(options[:reaction], env)
  result if Array === result and result.size == 3
end
referrer(env) click to toggle source
# File lib/rack/protection/base.rb, line 79
def referrer(env)
  ref = env['HTTP_REFERER'].to_s
  return if !options[:allow_empty_referrer] and ref.empty?
  URI.parse(ref).host || Request.new(env).host
end
safe?(env) click to toggle source
# File lib/rack/protection/base.rb, line 35
def safe?(env)
  %w[GET HEAD OPTIONS TRACE].include? env['REQUEST_METHOD']
end
session(env) click to toggle source
# File lib/rack/protection/base.rb, line 70
def session(env)
  return env[options[:session_key]] if session? env
  fail "you need to set up a session middleware *before* #{self.class}"
end
session?(env) click to toggle source
# File lib/rack/protection/base.rb, line 66
def session?(env)
  env.include? options[:session_key]
end
warn(env, message) click to toggle source
# File lib/rack/protection/base.rb, line 56
def warn(env, message)
  return unless options[:logging]
  l = options[:logger] || env['rack.logger'] || ::Logger.new(env['rack.errors'])
  l.warn(message)
end