Where the code lives
Every file below is in jodapp-api. The table is grouped the way the other pages are: endpoints, the session models, the cookies, the jobs, configuration.
The endpoints
| File | What it holds |
|---|---|
config/routes/identities_routes.rb | The four user session routes under /identities/user_sessions, the org_memberships route, and the password routes |
config/routes/team_routes.rb | The four admin session routes under /team/identities/admin_sessions, and the admin password route |
app/controllers/identities/user_sessions_controller.rb | User login, read the current session, logout, and sign out everywhere |
app/controllers/team/identities/admin_sessions_controller.rb | The admin twin |
app/domains/identities/user_sessions/create_manager.rb | The login checks: the rate limit, the password, the deleted and unverified rules, then the Identities::UserSession |
app/domains/identities/admin_sessions/create_manager.rb | The admin twin |
app/domains/identities/user_sessions/show_manager.rb and current_serializer.rb | Build the current-session JSON. Three serializers beside them shape its keys: user_serializer.rb, talent_access_serializer.rb and employer_access_serializer.rb |
app/controllers/identities/users/org_memberships_controller.rb | The signed-in user's own org_memberships list |
app/domains/identities/users/org_memberships_index_manager.rb, org_membership_serializer.rb and org_company_serializer.rb | The one query behind that list, and the shape of each entry and its company |
app/controllers/identities/users/passwords_controller.rb | The password reset, which ends every session of the person |
app/controllers/team/identities/admins/passwords_controller.rb | The admin twin |
The lookup on every request
| File | What it holds |
|---|---|
app/controllers/identities/users/authenticated_controller.rb | The base controller for user endpoints. Its authenticate runs the lookup, sets CurrentRequest.identities_user and CurrentRequest.identities_user_session, and answers 401 |
app/controllers/team/authenticated_controller.rb | The admin twin, with CurrentRequest.identities_admin and CurrentRequest.identities_admin_session |
app/models/current_request.rb | The ActiveSupport::CurrentAttributes that hold the owner and the session for the rest of the request |
The session models
| File | What it holds |
|---|---|
app/domains/identities/user_session.rb | Identities::UserSession: belongs_to :identities_user, the not_expired scope, the touch |
app/domains/identities/admin_session.rb | Identities::AdminSession, the twin |
app/domains/identities/user.rb and admin.rb | The owners. Each has_many its sessions, dependent: :destroy |
db/migrate/*_create_identities_user_sessions.rb and *_create_identities_admin_sessions.rb | The two tables |
docs/db/identities.dbml | The schema truth for both tables. A column exists only when it is written here |
The cookies and CSRF
| File | What it holds |
|---|---|
app/controllers/concerns/session_cookie_manager.rb | Sets the two cookies at login and deletes them at logout, with the attributes from the cookies page |
app/controllers/identities/users/authenticated_controller.rb | The CSRF comparison for cookie-authenticated writes, and the two 403 codes |
config/environments/production.rb, qa.rb, development.rb, test.rb | config.x.session_cookie_domains and config.hosts per environment |
config/initializers/cors.rb | The web origins allowed to call the API with cookies |
The jobs that delete expired sessions
| File | What it holds |
|---|---|
app/jobs/identities/delete_expired_user_sessions_job.rb | Identities::DeleteExpiredUserSessionsJob, watched in the Sidekiq admin panel's "Recurring Jobs" tab |
app/jobs/identities/delete_expired_admin_sessions_job.rb | The admin twin, watched the same way |
config/sidekiq_scheduler.yml | The two hourly entries |
config/initializers/sidekiq.rb | The error handler that sends a failed job to Sentry |
Configuration
| File | What it holds |
|---|---|
config/application.rb | config.x.sessions: the idle and absolute limits per identity system, and the touch interval |
config/initializers/filter_parameter_logging.rb | Keeps passwords and tokens out of the logs |
Tests
| File | What it covers |
|---|---|
test/controllers/identities/user_sessions_controller_test.rb | The four user endpoints, every line of the error table, and the cookie attributes |
test/controllers/team/identities/admin_sessions_controller_test.rb | The admin twin |
test/domains/identities/user_session_test.rb | The not_expired scope at each limit, and the touch interval |
test/jobs/identities/delete_expired_user_sessions_job_test.rb | Deletes only expired sessions, in batches |