Add oauth_login_counter before request phase middleware

What does this MR do and why?

The omniauth gem allows us to add custom logic to the different phases of the OAuth flow. Currently, the custom logic in the before_request_phase increments the login counter for the user.

As part of another MR, there is the intention to add more custom logic to the before_request_phase callback, see !171643 (diffs). For better maintenance, I see the potential to extract the current custom logic (that increases the login counter) into a separate class.

A similar approach is also used for the request_validation_phase, see https://gitlab.com/gitlab-community/gitlab/-/blob/master/config/initializers/omniauth.rb#L18 . In this "phase", the custom logic is encapsulated in the Gitlab::RequestForgeryProtection.

🛠️ with ❤️ at Siemens

References

Please include cross links to any resources that are relevant to this MR This will give reviewers and future readers helpful context to give an efficient review of the changes introduced.

MR acceptance checklist

Please evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

MR Checklist (@gerardo-navarro)

Screenshots or screen recordings

Only changes in the backend

How to set up and validate locally

  1. Run the relevant tests
bundle exec rspec spec/requests/rack_middlewares/omniauth_spec.rb spec/lib/gitlab/auth/o_auth/before_request_phase_oauth_login_counter_increment_spec.rb

Related to #512326 (closed)

Edited by Gerardo Navarro

Merge request reports

Loading