Skip to main content

Where the code lives

Every file below is in jodapp-api. The table is grouped the way the other pages are: endpoints, the session models, the cookies, the jobs, configuration.

The endpoints​

FileWhat it holds
config/routes/identities_routes.rbThe four user session routes under /identities/user_sessions, the org_memberships route, and the password routes
config/routes/team_routes.rbThe four admin session routes under /team/identities/admin_sessions, and the admin password route
app/controllers/identities/user_sessions_controller.rbUser login, read the current session, logout, and sign out everywhere
app/controllers/team/identities/admin_sessions_controller.rbThe admin twin
app/domains/identities/user_sessions/create_manager.rbThe login checks: the rate limit, the password, the deleted and unverified rules, then the Identities::UserSession
app/domains/identities/admin_sessions/create_manager.rbThe admin twin
app/domains/identities/user_sessions/show_manager.rb and current_serializer.rbBuild the current-session JSON. Three serializers beside them shape its keys: user_serializer.rb, talent_access_serializer.rb and employer_access_serializer.rb
app/controllers/identities/users/org_memberships_controller.rbThe signed-in user's own org_memberships list
app/domains/identities/users/org_memberships_index_manager.rb, org_membership_serializer.rb and org_company_serializer.rbThe one query behind that list, and the shape of each entry and its company
app/controllers/identities/users/passwords_controller.rbThe password reset, which ends every session of the person
app/controllers/team/identities/admins/passwords_controller.rbThe admin twin

The lookup on every request​

FileWhat it holds
app/controllers/identities/users/authenticated_controller.rbThe base controller for user endpoints. Its authenticate runs the lookup, sets CurrentRequest.identities_user and CurrentRequest.identities_user_session, and answers 401
app/controllers/team/authenticated_controller.rbThe admin twin, with CurrentRequest.identities_admin and CurrentRequest.identities_admin_session
app/models/current_request.rbThe ActiveSupport::CurrentAttributes that hold the owner and the session for the rest of the request

The session models​

FileWhat it holds
app/domains/identities/user_session.rbIdentities::UserSession: belongs_to :identities_user, the not_expired scope, the touch
app/domains/identities/admin_session.rbIdentities::AdminSession, the twin
app/domains/identities/user.rb and admin.rbThe owners. Each has_many its sessions, dependent: :destroy
db/migrate/*_create_identities_user_sessions.rb and *_create_identities_admin_sessions.rbThe two tables
docs/db/identities.dbmlThe schema truth for both tables. A column exists only when it is written here

The cookies and CSRF​

FileWhat it holds
app/controllers/concerns/session_cookie_manager.rbSets the two cookies at login and deletes them at logout, with the attributes from the cookies page
app/controllers/identities/users/authenticated_controller.rbThe CSRF comparison for cookie-authenticated writes, and the two 403 codes
config/environments/production.rb, qa.rb, development.rb, test.rbconfig.x.session_cookie_domains and config.hosts per environment
config/initializers/cors.rbThe web origins allowed to call the API with cookies

The jobs that delete expired sessions​

FileWhat it holds
app/jobs/identities/delete_expired_user_sessions_job.rbIdentities::DeleteExpiredUserSessionsJob, watched in the Sidekiq admin panel's "Recurring Jobs" tab
app/jobs/identities/delete_expired_admin_sessions_job.rbThe admin twin, watched the same way
config/sidekiq_scheduler.ymlThe two hourly entries
config/initializers/sidekiq.rbThe error handler that sends a failed job to Sentry

Configuration​

FileWhat it holds
config/application.rbconfig.x.sessions: the idle and absolute limits per identity system, and the touch interval
config/initializers/filter_parameter_logging.rbKeeps passwords and tokens out of the logs

Tests​

FileWhat it covers
test/controllers/identities/user_sessions_controller_test.rbThe four user endpoints, every line of the error table, and the cookie attributes
test/controllers/team/identities/admin_sessions_controller_test.rbThe admin twin
test/domains/identities/user_session_test.rbThe not_expired scope at each limit, and the touch interval
test/jobs/identities/delete_expired_user_sessions_job_test.rbDeletes only expired sessions, in batches