Complex classes like IdTokenBuilder often do a lot of different things. To break such a class down, we need to identify a cohesive component within that class. A common approach to find such a component is to look for fields/methods that share the same prefixes, or suffixes. You can also have a look at the cohesion graph to spot any un-connected, or weakly-connected components.
Once you have determined the fields that belong together, you can apply the Extract Class refactoring. If the component makes sense as a sub-class, Extract Subclass is also a candidate, and is often faster.
While breaking up the class, it is a good idea to analyze how other classes use IdTokenBuilder, and based on these observations, apply Extract Interface, too.
1 | <?php |
||
32 | final class IdTokenBuilder |
||
33 | { |
||
34 | /** |
||
35 | * @var string |
||
36 | */ |
||
37 | private $issuer; |
||
38 | |||
39 | /** |
||
40 | * @var Client |
||
41 | */ |
||
42 | private $client; |
||
43 | |||
44 | /** |
||
45 | * @var UserAccountInterface |
||
46 | */ |
||
47 | private $userAccount; |
||
48 | |||
49 | /** |
||
50 | * @var string |
||
51 | */ |
||
52 | private $redirectUri; |
||
53 | |||
54 | /** |
||
55 | * @var UserInfo |
||
56 | */ |
||
57 | private $userinfo; |
||
58 | |||
59 | /** |
||
60 | * @var JWKSet |
||
61 | */ |
||
62 | private $signatureKeys; |
||
63 | |||
64 | /** |
||
65 | * @var int |
||
66 | */ |
||
67 | private $lifetime; |
||
68 | |||
69 | /** |
||
70 | * @var string[] |
||
71 | */ |
||
72 | private $scopes = []; |
||
73 | |||
74 | /** |
||
75 | * @var array |
||
76 | */ |
||
77 | private $requestedClaims = []; |
||
78 | |||
79 | /** |
||
80 | * @var string|null |
||
81 | */ |
||
82 | private $claimsLocales = null; |
||
83 | |||
84 | /** |
||
85 | * @var AccessTokenId|null |
||
86 | */ |
||
87 | private $accessTokenId = null; |
||
88 | |||
89 | /** |
||
90 | * @var AuthCodeId|null |
||
91 | */ |
||
92 | private $authCodeId = null; |
||
93 | |||
94 | /** |
||
95 | * @var string|null |
||
96 | */ |
||
97 | private $nonce = null; |
||
98 | |||
99 | /** |
||
100 | * @var bool |
||
101 | */ |
||
102 | private $withAuthenticationTime = false; |
||
103 | |||
104 | /** |
||
105 | * @var JWSBuilder|null |
||
106 | */ |
||
107 | private $jwsBuilder = null; |
||
108 | |||
109 | /** |
||
110 | * @var string|null |
||
111 | */ |
||
112 | private $signatureAlgorithm = null; |
||
113 | |||
114 | /** |
||
115 | * @var JWEBuilder|null |
||
116 | */ |
||
117 | private $jweBuilder; |
||
118 | |||
119 | /** |
||
120 | * @var string|null |
||
121 | */ |
||
122 | private $keyEncryptionAlgorithm = null; |
||
123 | |||
124 | /** |
||
125 | * @var string|null |
||
126 | */ |
||
127 | private $contentEncryptionAlgorithm = null; |
||
128 | |||
129 | /** |
||
130 | * @var \DateTimeImmutable|null |
||
131 | */ |
||
132 | private $expiresAt = null; |
||
133 | |||
134 | /** |
||
135 | * IdTokenBuilder constructor. |
||
136 | * |
||
137 | * @param string $issuer |
||
138 | * @param UserInfo $userinfo |
||
139 | * @param int $lifetime |
||
140 | * @param Client $client |
||
141 | * @param UserAccountInterface $userAccount |
||
142 | * @param string $redirectUri |
||
143 | */ |
||
144 | private function __construct(string $issuer, UserInfo $userinfo, int $lifetime, Client $client, UserAccountInterface $userAccount, string $redirectUri) |
||
153 | |||
154 | /** |
||
155 | * @param string $issuer |
||
156 | * @param UserInfo $userinfo |
||
157 | * @param int $lifetime |
||
158 | * @param Client $client |
||
159 | * @param UserAccountInterface $userAccount |
||
160 | * @param string $redirectUri |
||
161 | * |
||
162 | * @return IdTokenBuilder |
||
163 | */ |
||
164 | public static function create(string $issuer, UserInfo $userinfo, int $lifetime, Client $client, UserAccountInterface $userAccount, string $redirectUri) |
||
168 | |||
169 | /** |
||
170 | * @param AccessToken $accessToken |
||
171 | * |
||
172 | * @return IdTokenBuilder |
||
173 | */ |
||
174 | public function withAccessToken(AccessToken $accessToken): IdTokenBuilder |
||
195 | |||
196 | /** |
||
197 | * @param AccessTokenId $accessTokenId |
||
198 | * |
||
199 | * @return IdTokenBuilder |
||
200 | */ |
||
201 | public function withAccessTokenId(AccessTokenId $accessTokenId): IdTokenBuilder |
||
208 | |||
209 | /** |
||
210 | * @param AuthCodeId $authCodeId |
||
211 | * |
||
212 | * @return IdTokenBuilder |
||
213 | */ |
||
214 | public function withAuthCodeId(AuthCodeId $authCodeId): IdTokenBuilder |
||
221 | |||
222 | /** |
||
223 | * @param string $claimsLocales |
||
224 | * |
||
225 | * @return IdTokenBuilder |
||
226 | */ |
||
227 | public function withClaimsLocales(string $claimsLocales): IdTokenBuilder |
||
234 | |||
235 | /** |
||
236 | * @return IdTokenBuilder |
||
237 | */ |
||
238 | public function withAuthenticationTime(): IdTokenBuilder |
||
245 | |||
246 | /** |
||
247 | * @param string[] $scopes |
||
248 | * |
||
249 | * @return IdTokenBuilder |
||
250 | */ |
||
251 | public function withScope(array $scopes): IdTokenBuilder |
||
258 | |||
259 | /** |
||
260 | * @param array $requestedClaims |
||
261 | * |
||
262 | * @return IdTokenBuilder |
||
263 | */ |
||
264 | public function withRequestedClaims(array $requestedClaims): IdTokenBuilder |
||
271 | |||
272 | /** |
||
273 | * @param string $nonce |
||
274 | * |
||
275 | * @return IdTokenBuilder |
||
276 | */ |
||
277 | public function withNonce(string $nonce): IdTokenBuilder |
||
284 | |||
285 | /** |
||
286 | * @param \DateTimeImmutable $expiresAt |
||
287 | * |
||
288 | * @return IdTokenBuilder |
||
289 | */ |
||
290 | public function withExpirationAt(\DateTimeImmutable $expiresAt): IdTokenBuilder |
||
297 | |||
298 | /** |
||
299 | * @return IdTokenBuilder |
||
300 | */ |
||
301 | public function withoutAuthenticationTime(): IdTokenBuilder |
||
308 | |||
309 | /** |
||
310 | * @param JWSBuilder $jwsBuilder |
||
311 | * @param JWKSet $signatureKeys |
||
312 | * @param string $signatureAlgorithm |
||
313 | * |
||
314 | * @return IdTokenBuilder |
||
315 | */ |
||
316 | public function withSignature(JWSBuilder $jwsBuilder, JWKSet $signatureKeys, string $signatureAlgorithm): IdTokenBuilder |
||
327 | |||
328 | /** |
||
329 | * @param JWEBuilder $jweBuilder |
||
330 | * @param string $keyEncryptionAlgorithm |
||
331 | * @param string $contentEncryptionAlgorithm |
||
332 | * |
||
333 | * @return IdTokenBuilder |
||
334 | */ |
||
335 | public function withEncryption(JWEBuilder $jweBuilder, string $keyEncryptionAlgorithm, string $contentEncryptionAlgorithm): IdTokenBuilder |
||
346 | |||
347 | /** |
||
348 | * @return string |
||
349 | */ |
||
350 | public function build(): string |
||
371 | |||
372 | /** |
||
373 | * @param array $claims |
||
374 | * |
||
375 | * @return array |
||
376 | */ |
||
377 | private function updateClaimsWithJwtClaims(array $claims): array |
||
393 | |||
394 | /** |
||
395 | * @param array $claims |
||
396 | * @param UserAccountInterface $userAccount |
||
397 | * |
||
398 | * @return array |
||
399 | */ |
||
400 | private function updateClaimsWithAuthenticationTime(array $claims, UserAccountInterface $userAccount): array |
||
408 | |||
409 | /** |
||
410 | * @param array $claims |
||
411 | * |
||
412 | * @return array |
||
413 | */ |
||
414 | private function updateClaimsWithNonce(array $claims): array |
||
422 | |||
423 | /** |
||
424 | * @param array $claims |
||
425 | * |
||
426 | * @return array |
||
427 | */ |
||
428 | private function updateClaimsAudience(array $claims): array |
||
437 | |||
438 | /** |
||
439 | * @param array $claims |
||
440 | * @param UserAccountInterface $userAccount |
||
441 | * |
||
442 | * @return array |
||
443 | */ |
||
444 | private function updateClaimsWithAmrAndAcrInfo(array $claims, UserAccountInterface $userAccount): array |
||
454 | |||
455 | /** |
||
456 | * @param array $claims |
||
457 | * |
||
458 | * @return string |
||
459 | */ |
||
460 | private function computeIdToken(array $claims): string |
||
473 | |||
474 | /** |
||
475 | * @param Client $client |
||
476 | * @param string $jwt |
||
477 | * |
||
478 | * @return string |
||
479 | */ |
||
480 | private function tryToEncrypt(Client $client, string $jwt): string |
||
502 | |||
503 | /** |
||
504 | * @param string $signatureAlgorithm |
||
505 | * |
||
506 | * @return JWK |
||
507 | */ |
||
508 | private function getSignatureKey(string $signatureAlgorithm): JWK |
||
519 | |||
520 | /** |
||
521 | * @param JWK $signatureKey |
||
522 | * @param string $signatureAlgorithm |
||
523 | * |
||
524 | * @return array |
||
525 | */ |
||
526 | private function getHeaders(JWK $signatureKey, string $signatureAlgorithm): array |
||
538 | |||
539 | /** |
||
540 | * @param array $claims |
||
541 | * |
||
542 | * @return array |
||
543 | */ |
||
544 | private function updateClaimsWithTokenHash(array $claims): array |
||
558 | |||
559 | /** |
||
560 | * @param TokenId $tokenId |
||
561 | * |
||
562 | * @return string |
||
563 | */ |
||
564 | private function getHash(TokenId $tokenId): string |
||
568 | |||
569 | /** |
||
570 | * @throws \InvalidArgumentException |
||
571 | * |
||
572 | * @return string |
||
573 | */ |
||
574 | private function getHashMethod(): string |
||
595 | |||
596 | /** |
||
597 | * @throws \InvalidArgumentException |
||
598 | * |
||
599 | * @return int |
||
600 | */ |
||
601 | private function getHashSize(): int |
||
622 | } |
||
623 |