Thin, Sinatra and static file interception for CAS authentication
I am using casrack-the-authenticator gem for CAS authentication. My server is running Thin on top of Sinatra. I got the CAS authentication bit, but I'm not sure how to tell Rack to intercept the "/index.html" requests to confirm CAS login, and if the user is not allowed to view the page, return HTTP 403 instead of serving the actual page. Anyone have any experience? Thanks.
My application:
class Foo < Sinatra::Base
enable :sessions
set :public, "public"
use CasrackTheAuthenticator::Simple, :cas_server => "https://my.cas_server.com"
use CasrackTheAuthenticator::RequireCAS
get '/' do
puts "Hello World"
end
end
My rack file:
require 'foo'
use Rack::CommonLogger
use Rack::Lint
run Foo
Initial attempt at getting the rack to understand authentication on its fileservice (comments and thoughts are appreciated):
builder = Rack::Builder.new do
map '/foo/index.html' do
run Proc.new { |env|
user = Rack::Request.new(env).session[CasrackTheAuthenticator::USERNAME_PARAM]
[401, { "Content-Type" => "text/html" }, "CAS Authentication Required"] unless user
# Serve index.html because we detected user
}
end
map '/foo' do
run Foo
end
end
run builder
a source to share
Casrack-the-Authenticator puts CAS information into the Rack session. You can pull this into another piece of Rack middleware or your Sinatra app.
Below is a Rails application, but the concept is the same for Sinatra or Rack middleware:
# in app/controllers/application_controller.rb:
protected
def require_sign_in!
render :nothing => true, :status => 403 unless signed_in?
end
def signed_in?
current_user.present?
end
def current_user
@current_user ||= Person.find_by_username(session[CasrackTheAuthenticator::USERNAME_PARAM])
end
a source to share