heartcombo--devise/lib/devise/hooks/timeoutable.rb

19 lines
783 B
Ruby
Raw Normal View History

2009-11-23 01:29:03 +00:00
# Each time a record is set we check whether it's session has already timed out
# or not, based on last request time. If so, the record is logged out and
# redirected to the sign in page. Also, each time the request comes and the
# record is set, we set the last request time inside it's scoped session to
# verify timeout in the following request.
Warden::Manager.after_set_user do |record, warden, options|
scope = options[:scope]
2010-01-14 14:47:14 +00:00
if record && record.respond_to?(:timedout?) && warden.authenticated?(scope)
last_request_at = warden.session(scope)['last_request_at']
2010-01-14 14:47:14 +00:00
if record.timedout?(last_request_at)
warden.logout(scope)
throw :warden, :scope => scope, :message => :timeout
end
2010-01-14 14:47:14 +00:00
warden.session(scope)['last_request_at'] = Time.now.utc
end
end