Repository navigation
Expand file tree
/
Copy pathapp.rb
More file actions
108 lines (88 loc) · 2.66 KB
/
Copy pathapp.rb
File metadata and controls
108 lines (88 loc) · 2.66 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
require 'sinatra'
require 'gon-sinatra'
require 'octokit'
require_relative "lib/get_functions"
CLIENT_ID = ENV['CLIENT_ID']
CLIENT_SECRET = ENV['CLIENT_SECRET']
use Rack::Session::Pool
Sinatra::register Gon::Sinatra
configure do
set :server, :puma
set :bind, "0.0.0.0"
set :protection, except: [:frame_options, :json_csrf]
set :root, File.dirname(__FILE__)
# this added in attempt to "forbidden" response when clicking on links
#set :protection, :except => :ip_spoofing
#set :protection, :except => :json
end
if settings.development?
require 'pry'
end
# authentation code taken from https://developer.github.com/v3/guides/basics-of-authentication/ and http://radek.io/2014/08/03/github-oauth-with-octokit/
def authenticated?
session[:access_token]
end
def authenticate!
client = Octokit::Client.new
scopes = ['repo', 'user']
url = client.authorize_url(CLIENT_ID, :scope => 'repo')
redirect url
end
# index route
get '/' do
if !authenticated?
authenticate!
else
access_token = session[:access_token]
scopes = []
client = Octokit::Client.new \
:client_id => CLIENT_ID,
:client_secret => CLIENT_SECRET
begin
client.check_application_authorization access_token
rescue => e
# request didn't succeed because the token was revoked so we
# invalidate the token stored in the session and render the
# index page so that the user can start the OAuth flow again
session[:access_token] = nil
return authenticate!
end
# doesn't necessarily need to go in 'editor'
redirect '/editor'
end
end
# step two in the oauth process
# github redirects here
# if auth_token is not already set, auth_token and other desirable data are set to environmental variables
get '/return' do
# get code return from github and get access token
session_code = request.env['rack.request.query_hash']['code']
result = Octokit.exchange_code_for_token(session_code, CLIENT_ID, CLIENT_SECRET)
session[:access_token] = result[:access_token]
redirect '/'
end
# STEP 3 return user to main edit page
# main edit page
get '/editor' do
if !authenticated?
authenticate!
end
client = Octokit::Client.new :access_token => session[:access_token]
data = client.user
@username = data.login
@user_url = data.html_url
gon.access_token = session[:access_token]
gon.username = @username
erb :editor
end
## just returns parsed doc
## required for ajax reques
# this could likely be done entirely in javascript
get '/doc' do
client = Octokit::Client.new :access_token => session[:access_token]
data = client.user
@username = data.login
@user_url = data.html_url
@doc = get_doc_from_template
return @doc
end