Failed Conditions
Pull Request — master (#31)
by Florent
03:43
created

IdTokenEncryptionSource::continueLoading()   A

Complexity

Conditions 2
Paths 2

Size

Total Lines 7
Code Lines 4

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
dl 0
loc 7
rs 9.4285
c 0
b 0
f 0
cc 2
eloc 4
nc 2
nop 3
1
<?php
2
3
declare(strict_types=1);
4
5
/*
6
 * The MIT License (MIT)
7
 *
8
 * Copyright (c) 2014-2017 Spomky-Labs
9
 *
10
 * This software may be modified and distributed under the terms
11
 * of the MIT license.  See the LICENSE file for details.
12
 */
13
14
namespace OAuth2Framework\Bundle\Server\DependencyInjection\Source\OpenIdConnect;
15
16
use OAuth2Framework\Bundle\Server\DependencyInjection\Source\ActionableSource;
17
use SpomkyLabs\JoseBundle\Helper\ConfigurationHelper;
18
use Symfony\Component\Config\Definition\Builder\NodeDefinition;
19
use Symfony\Component\DependencyInjection\ContainerBuilder;
20
use Symfony\Component\PropertyAccess\PropertyAccess;
21
22
final class IdTokenEncryptionSource extends ActionableSource
23
{
24
    /**
25
     * {@inheritdoc}
26
     */
27
    protected function continueLoading(string $path, ContainerBuilder $container, array $config)
28
    {
29
        foreach (['key_encryption_algorithms', 'content_encryption_algorithms'] as $k) {
30
            $container->setParameter($path.'.'.$k, $config[$k]);
31
        }
32
        $container->setAlias($path.'.key_set', $config['key_set']);
33
    }
34
35
    /**
36
     * {@inheritdoc}
37
     */
38
    public function prepend(array $bundleConfig, string $path, ContainerBuilder $container)
39
    {
40
        $currentPath = $path.'['.$this->name().']';
41
        $accessor = PropertyAccess::createPropertyAccessor();
42
        $sourceConfig = $accessor->getValue($bundleConfig, $currentPath);
43
44
        if (true === $sourceConfig['enabled']) {
45
            $this->updateJoseBundleConfigurationForEncrypter($container, $sourceConfig);
46
            $this->updateJoseBundleConfigurationForDecrypter($container, $sourceConfig);
47
        }
48
    }
49
50
    /**
51
     * {@inheritdoc}
52
     */
53
    protected function name(): string
54
    {
55
        return 'encryption';
56
    }
57
58
    protected function continueConfiguration(NodeDefinition $node)
59
    {
60
        parent::continueConfiguration($node);
61
        $node
0 ignored issues
show
Bug introduced by
It seems like you code against a specific sub-type and not the parent class Symfony\Component\Config...\Builder\NodeDefinition as the method children() does only exist in the following sub-classes of Symfony\Component\Config...\Builder\NodeDefinition: Symfony\Component\Config...der\ArrayNodeDefinition. Maybe you want to instanceof check for one of these explicitly?

Let’s take a look at an example:

abstract class User
{
    /** @return string */
    abstract public function getPassword();
}

class MyUser extends User
{
    public function getPassword()
    {
        // return something
    }

    public function getDisplayName()
    {
        // return some name.
    }
}

class AuthSystem
{
    public function authenticate(User $user)
    {
        $this->logger->info(sprintf('Authenticating %s.', $user->getDisplayName()));
        // do something.
    }
}

In the above example, the authenticate() method works fine as long as you just pass instances of MyUser. However, if you now also want to pass a different sub-classes of User which does not have a getDisplayName() method, the code will break.

Available Fixes

  1. Change the type-hint for the parameter:

    class AuthSystem
    {
        public function authenticate(MyUser $user) { /* ... */ }
    }
    
  2. Add an additional type-check:

    class AuthSystem
    {
        public function authenticate(User $user)
        {
            if ($user instanceof MyUser) {
                $this->logger->info(/** ... */);
            }
    
            // or alternatively
            if ( ! $user instanceof MyUser) {
                throw new \LogicException(
                    '$user must be an instance of MyUser, '
                   .'other instances are not supported.'
                );
            }
    
        }
    }
    
Note: PHP Analyzer uses reverse abstract interpretation to narrow down the types inside the if block in such a case.
  1. Add the method to the parent class:

    abstract class User
    {
        /** @return string */
        abstract public function getPassword();
    
        /** @return string */
        abstract public function getDisplayName();
    }
    
Loading history...
62
            ->children()
63
                ->scalarNode('key_set')
64
                    ->info('Key set that contains a suitable encryption key for the selected encryption algorithms.')
65
                    ->defaultNull()
66
                ->end()
67
                ->arrayNode('key_encryption_algorithms')
68
                    ->info('Supported key encryption algorithms.')
69
                    ->useAttributeAsKey('name')
70
                    ->prototype('scalar')->end()
71
                    ->treatNullLike([])
72
                ->end()
73
                ->arrayNode('content_encryption_algorithms')
74
                    ->info('Supported content encryption algorithms.')
75
                    ->useAttributeAsKey('name')
76
                    ->prototype('scalar')->end()
77
                    ->treatNullLike([])
78
                ->end()
79
            ->end();
80
    }
81
82
    /**
83
     * @param ContainerBuilder $container
84
     * @param array            $sourceConfig
85
     */
86
    private function updateJoseBundleConfigurationForEncrypter(ContainerBuilder $container, array $sourceConfig)
87
    {
88
        ConfigurationHelper::addEncrypter($container, 'id_token', $sourceConfig['key_encryption_algorithms'], $sourceConfig['content_encryption_algorithms'], ['DEF'], false, false);
89
    }
90
91
    /**
92
     * @param ContainerBuilder $container
93
     * @param array            $sourceConfig
94
     */
95
    private function updateJoseBundleConfigurationForDecrypter(ContainerBuilder $container, array $sourceConfig)
96
    {
97
        ConfigurationHelper::addDecrypter($container, 'id_token', $sourceConfig['key_encryption_algorithms'], $sourceConfig['content_encryption_algorithms'], ['DEF'], false);
98
    }
99
}
100