如何扩展Clearance的后门以支持双因素认证(2FA)。

huangapple go评论71阅读模式
英文:

How to extend clearance's back door to allow for 2FA

问题

我有一个应用程序,它使用Clearance gem进行身份验证,但也实现了两步验证(2FA)。我想在测试中使用Clearance的“后门”功能,但不确定如何与2FA结合使用。

是否有一种方式可以“挂钩”到Clearance的后门功能,并在每次使用它进行登录时设置所需的2FA值?

英文:

I have an application which uses the Clearance gem for authentication, but also implements 2FA. I want to use the "Backdoor" functionality of Clearance for tests, but am unsure how to do this in conjunction with 2FA.

Is there a way I can "hook into" Clearance's Backdoor functionality and set the required 2FA values whenever it is used to sign in?

答案1

得分: 0

基于Clearance::Backdoor的源代码,如果你想在用户模型上设置额外的值,这可能会起作用:

  1. # config/environments/test.rb
  2. MyRailsApp::Application.configure do
  3. # ...
  4. config.middleware.use Clearance::BackDoor do |username|
  5. user = User.find_by(username: username) # 或者你找到用户的方式
  6. # 设置你的额外值
  7. user.x = 'x'
  8. user.y = 'y'
  9. # 返回用户
  10. user
  11. end
  12. end

如果你想修改请求,我认为你不能使用Clearance::Backdoor,但你可以在它之后添加另一个Rack中间件,使用config.middleware.insert_after(Clearance::Backdoor)(你需要编写自己的中间件)。

作为替代方案,我见过很多测试只是模拟检查用户是否已登录的代码片段,并始终返回true(或者表示成功的任何值)。

英文:

Based on the source of Clearance::Backdoor, if you're trying to set extra values on a user model, this might work:

  1. # config/environments/test.rb
  2. MyRailsApp::Application.configure do
  3. # ...
  4. config.middleware.use Clearance::BackDoor do |username|
  5. user = User.find_by(username: username) # or however you'd find a user
  6. # set your extra values
  7. user.x = 'x'
  8. user.y = 'y'
  9. # return the user
  10. user
  11. end
  12. end

If you want to mess with the request I don't think you can use Clearance::Backdoor, but you could add another Rack middleware after it using config.middleware.insert_after(Clearance::Backdoor) (you would have to write your own middleware).

As an alternative, a lot of tests I've seen just mock the piece of code that checks whether a user is signed in, and make it always return true (or whatever indicates success).

huangapple
  • 本文由 发表于 2023年1月9日 17:51:13
  • 转载请务必保留本文链接:https://go.coder-hub.com/75055532.html
匿名

发表评论

匿名网友

:?: :razz: :sad: :evil: :!: :smile: :oops: :grin: :eek: :shock: :???: :cool: :lol: :mad: :twisted: :roll: :wink: :idea: :arrow: :neutral: :cry: :mrgreen:

确定