| Total Complexity | 62 |
| Total Lines | 298 |
| Duplicated Lines | 0 % |
| Changes | 1 | ||
| Bugs | 1 | Features | 0 |
Complex classes like preferences_password often do a lot of different things. To break such a class down, we need to identify a cohesive component within that class. A common approach to find such a component is to look for fields/methods that share the same prefixes, or suffixes.
Once you have determined the fields that belong together, you can apply the Extract Class refactoring. If the component makes sense as a sub-class, Extract Subclass is also a candidate, and is often faster.
While breaking up the class, it is a good idea to analyze how other classes use preferences_password, and based on these observations, apply Extract Interface, too.
| 1 | <?php |
||
| 23 | class preferences_password |
||
| 24 | { |
||
| 25 | var $public_functions = array( |
||
| 26 | 'change' => True |
||
| 27 | ); |
||
| 28 | const GAUTH_ANDROID = 'https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2'; |
||
| 29 | const GAUTH_IOS = 'https://appstore.com/googleauthenticator'; |
||
| 30 | |||
| 31 | /** |
||
| 32 | * Change password, two factor auth or revoke tokens |
||
| 33 | * |
||
| 34 | * @param type $content |
||
| 35 | */ |
||
| 36 | function change($content = null) |
||
| 37 | { |
||
| 38 | $GLOBALS['egw_info']['flags']['app_header'] = lang('Security & Password'); |
||
| 39 | $tmpl = new Etemplate('preferences.password'); |
||
| 40 | |||
| 41 | $readonlys = $sel_options = []; |
||
| 42 | try { |
||
| 43 | // PHP 7.1+: using SVG image backend (requiring XMLWriter) and not ImageMagic extension |
||
| 44 | if (class_exists('BaconQrCode\Renderer\Image\SvgImageBackEnd')) |
||
| 45 | { |
||
| 46 | $image_backend = new \BaconQrCode\Renderer\Image\SvgImageBackEnd; |
||
|
|
|||
| 47 | } |
||
| 48 | $google2fa = new Google2FA($image_backend); |
||
| 49 | $prefs = new Api\Preferences($GLOBALS['egw_info']['user']['account_id']); |
||
| 50 | $prefs->read_repository(); |
||
| 51 | |||
| 52 | if (!is_array($content)) |
||
| 53 | { |
||
| 54 | $content = []; |
||
| 55 | $content['2fa'] = $this->generateQRCode($google2fa)+[ |
||
| 56 | 'gauth_android' => self::GAUTH_ANDROID, |
||
| 57 | 'gauth_ios' => self::GAUTH_IOS, |
||
| 58 | ]; |
||
| 59 | } |
||
| 60 | else |
||
| 61 | { |
||
| 62 | $secret_key = $content['2fa']['secret_key']; |
||
| 63 | unset($content['2fa']['secret_key']); |
||
| 64 | |||
| 65 | // check user password for everything but password change, where it will be checked anyway |
||
| 66 | $auth = new Api\Auth(); |
||
| 67 | if ($content['tabs'] !== 'change_password' && |
||
| 68 | !$auth->authenticate($GLOBALS['egw_info']['user']['account_lid'], $content['password'])) |
||
| 69 | { |
||
| 70 | $tmpl->set_validation_error('password', lang('Password is invalid')); |
||
| 71 | } |
||
| 72 | else |
||
| 73 | { |
||
| 74 | switch($content['tabs']) |
||
| 75 | { |
||
| 76 | case 'change_password': |
||
| 77 | if (!$GLOBALS['egw']->acl->check('nopasswordchange', 1) && $content['button']['save']) |
||
| 78 | { |
||
| 79 | if (($errors = self::do_change($content['password'], $content['n_passwd'], $content['n_passwd_2']))) |
||
| 80 | { |
||
| 81 | Framework::message(implode("\n", $errors), 'error'); |
||
| 82 | } |
||
| 83 | else |
||
| 84 | { |
||
| 85 | Framework::refresh_opener(lang('Password changed'), 'preferences'); |
||
| 86 | Framework::window_close(); |
||
| 87 | } |
||
| 88 | } |
||
| 89 | break; |
||
| 90 | |||
| 91 | case 'two_factor_auth': |
||
| 92 | switch(key($content['2fa']['action'])) |
||
| 93 | { |
||
| 94 | case 'show': |
||
| 95 | $content['2fa'] = $this->generateQRCode($google2fa, false); |
||
| 96 | break; |
||
| 97 | case 'reset': |
||
| 98 | $content['2fa'] = $this->generateQRCode($google2fa, true); |
||
| 99 | Framework::message(lang('New secret generated, you need to save it to disable the old one!')); |
||
| 100 | break; |
||
| 101 | case 'disable': |
||
| 102 | if (Credentials::delete(0, $GLOBALS['egw_info']['user']['account_id'], Credentials::TWOFA)) |
||
| 103 | { |
||
| 104 | Framework::refresh_opener(lang('Secret deleted, two factor authentication disabled.'), 'preferences'); |
||
| 105 | Framework::window_close(); |
||
| 106 | } |
||
| 107 | else |
||
| 108 | { |
||
| 109 | Framework::message(lang('Failed to delete secret!'), 'error'); |
||
| 110 | } |
||
| 111 | break; |
||
| 112 | default: // no action, save secret |
||
| 113 | if (!$google2fa->verifyKey($secret_key, $content['2fa']['code'])) |
||
| 114 | { |
||
| 115 | $tmpl->set_validation_error('code', lang('Code is invalid'), '2fa'); |
||
| 116 | break 2; |
||
| 117 | } |
||
| 118 | if (($content['2fa']['cred_id'] = Credentials::write(0, |
||
| 119 | $GLOBALS['egw_info']['user']['account_lid'], |
||
| 120 | $secret_key, Credentials::TWOFA, |
||
| 121 | $GLOBALS['egw_info']['user']['account_id'], |
||
| 122 | $content['2fa']['cred_id']))) |
||
| 123 | { |
||
| 124 | Framework::refresh_opener(lang('Two Factor Auth enabled.'), 'preferences'); |
||
| 125 | Framework::window_close(); |
||
| 126 | } |
||
| 127 | else |
||
| 128 | { |
||
| 129 | Framework::message(lang('Failed to store secret!'), 'error'); |
||
| 130 | } |
||
| 131 | break; |
||
| 132 | } |
||
| 133 | unset($content['2fa']['action']); |
||
| 134 | break; |
||
| 135 | |||
| 136 | default: |
||
| 137 | // for other tabs call their save_callback (user password is already checked!) |
||
| 138 | if (!empty($content['save_callbacks'][$content['tabs']]) && |
||
| 139 | ($msg = call_user_func_array($content['save_callbacks'][$content['tabs']], [&$content]))) |
||
| 140 | { |
||
| 141 | Framework::message($msg, 'success'); |
||
| 142 | } |
||
| 143 | break; |
||
| 144 | } |
||
| 145 | } |
||
| 146 | } |
||
| 147 | } |
||
| 148 | catch (Exception $e) { |
||
| 149 | Framework::message($e->getMessage(), 'error'); |
||
| 150 | } |
||
| 151 | |||
| 152 | // disable 2FA tab, if admin disabled it |
||
| 153 | if ($GLOBALS['egw_info']['server']['2fa_required'] === 'disabled') |
||
| 154 | { |
||
| 155 | $readonlys['tabs']['two_factor_auth'] = true; |
||
| 156 | } |
||
| 157 | |||
| 158 | // disable password change, if user has not right to change it |
||
| 159 | if ($GLOBALS['egw']->acl->check('nopasswordchange', 1)) |
||
| 160 | { |
||
| 161 | $readonlys['tabs']['change_password'] = true; |
||
| 162 | } |
||
| 163 | |||
| 164 | $preserve = [ |
||
| 165 | '2fa' => $content['2fa']+[ |
||
| 166 | 'secret_key' => $secret_key, |
||
| 167 | ] |
||
| 168 | ]; |
||
| 169 | |||
| 170 | $tmpl->setElementAttribute('tabs', 'add_tabs', true); |
||
| 171 | $tabs =& $tmpl->getElementAttribute('tabs', 'tabs'); |
||
| 172 | if (($first_call = !isset($tabs))) |
||
| 173 | { |
||
| 174 | $tabs = array(); |
||
| 175 | } |
||
| 176 | // register hooks, if openid is available, but new hook not yet registered (should be removed after 19.1) |
||
| 177 | if (!empty($GLOBALS['egw_info']['apps']['openid']) && !Api\Hooks::implemented('preferences_security')) |
||
| 178 | { |
||
| 179 | Api\Hooks::read(true); |
||
| 180 | } |
||
| 181 | $hook_data = Api\Hooks::process(array('location' => 'preferences_security')+$content, ['openid'], true); |
||
| 182 | foreach($hook_data as $extra_tabs) |
||
| 183 | { |
||
| 184 | if (!$extra_tabs) continue; |
||
| 185 | |||
| 186 | foreach(isset($extra_tabs[0]) ? $extra_tabs : [$extra_tabs] as $extra_tab) |
||
| 187 | { |
||
| 188 | if (!empty($extra_tab['data']) && is_array($extra_tab['data'])) |
||
| 189 | { |
||
| 190 | $content = array_merge($content, $extra_tab['data']); |
||
| 191 | } |
||
| 192 | if (!empty($extra_tab['preserve']) && is_array($extra_tab['preserve'])) |
||
| 193 | { |
||
| 194 | $preserve = array_merge($preserve, $extra_tab['preserve']); |
||
| 195 | } |
||
| 196 | if (!empty($extra_tab['sel_options']) && is_array($extra_tab['sel_options'])) |
||
| 197 | { |
||
| 198 | $sel_options = array_merge($sel_options, $extra_tab['sel_options']); |
||
| 199 | } |
||
| 200 | if (!empty($extra_tab['readonlys']) && is_array($extra_tab['readonlys'])) |
||
| 201 | { |
||
| 202 | $readonlys = array_merge($readonlys, $extra_tab['readonlys']); |
||
| 203 | } |
||
| 204 | if (!empty($extra_tab['save_callback'])) |
||
| 205 | { |
||
| 206 | $preserve['save_callbacks'][$extra_tab['name']] = $extra_tab['save_callback']; |
||
| 207 | } |
||
| 208 | // we must NOT add tabs more then once! |
||
| 209 | if ($first_call && !empty($extra_tab['label']) && !empty($extra_tab['name'])) |
||
| 210 | { |
||
| 211 | $tabs[] = array( |
||
| 212 | 'label' => $extra_tab['label'], |
||
| 213 | 'template' => $extra_tab['name'], |
||
| 214 | 'prepend' => $extra_tab['prepend'], |
||
| 215 | ); |
||
| 216 | } |
||
| 217 | //error_log(__METHOD__."() changed tabs=".array2string($tabs)); |
||
| 218 | } |
||
| 219 | } |
||
| 220 | |||
| 221 | $tmpl->exec('preferences.preferences_password.change', $content, $sel_options, $readonlys, $preserve, 2); |
||
| 222 | } |
||
| 223 | |||
| 224 | /** |
||
| 225 | * Generate QRCode and optional new secret |
||
| 226 | * |
||
| 227 | * @param Google2FA $google2fa |
||
| 228 | * @param boolean|null $generate =null null: generate new qrCode/secret, if none exists |
||
| 229 | * true: allways generate new qrCode (to reset existing one) |
||
| 230 | * false: use existing secret, but generate qrCode |
||
| 231 | * @return array with keys "qrc" and "cred_id" |
||
| 232 | */ |
||
| 233 | protected function generateQRCode(Google2FA $google2fa, $generate=null) |
||
| 266 | ]; |
||
| 267 | } |
||
| 268 | |||
| 269 | /** |
||
| 270 | * Do some basic checks and then change password |
||
| 271 | * |
||
| 272 | * @param string $old_passwd |
||
| 273 | * @param string $new_passwd |
||
| 274 | * @param string $new_passwd2 |
||
| 275 | * @return array with already translated errors |
||
| 276 | */ |
||
| 277 | public static function do_change($old_passwd, $new_passwd, $new_passwd2) |
||
| 321 | } |
||
| 322 | } |
||
| 323 |
The issue could also be caused by a filter entry in the build configuration. If the path has been excluded in your configuration, e.g.
excluded_paths: ["lib/*"], you can move it to the dependency path list as follows:For further information see https://scrutinizer-ci.com/docs/tools/php/php-scrutinizer/#list-dependency-paths