Similarly to other answers I followed this approach, where the model storing the auth and refresh tokens is used, abstracting API interactions from that logic.
# Manages access tokens for users when using Google APIs
#
# Usage:
# require 'google/apis/gmail_v1'
# Gmail = Google::Apis::GmailV1 # Alias the module
# service = Gmail::GmailService.new
# service.authorization = GoogleOauth2Authorization.new user
# service.list_user_messages(user.email)
#
# See also:
# https://github.com/google/google-api-ruby-client/issues/296
class GoogleOauth2Authorization
attr_reader :user
def initialize(user)
@user = user
end
def apply!(headers)
headers['Authorization'] = "Bearer #{token}"
end
def token
refresh! if user.provider_token_expires_at.past?
user.provider_access_token
end
private
def refresh!
new_token = oauth_access_token(
user.provider_access_token,
user.provider_refresh_token
).refresh!
if new_token.present?
user.update(
provider_access_token: new_token.token,
provider_token_expires_at: Time.zone.at(new_token.expires_at),
provider_refresh_token: new_token.refresh_token
)
end
user
end
def oauth_access_token(access_token, refresh_token)
OAuth2::AccessToken.new(
oauth_strategy.client,
access_token,
refresh_token: refresh_token
)
end
def oauth_strategy
OmniAuth::Strategies::GoogleOauth2.new(
nil,
Rails.application.credentials.oauth[:google_id],
Rails.application.credentials.oauth[:google_secret]
)
end
end