1 | <?php |
||
32 | class SamlProvider implements AuthenticationProviderInterface |
||
33 | { |
||
34 | /** |
||
35 | * @var \Surfnet\StepupRa\RaBundle\Service\IdentityService |
||
36 | */ |
||
37 | private $identityService; |
||
38 | |||
39 | /** |
||
40 | * @var \Surfnet\SamlBundle\SAML2\Attribute\AttributeDictionary |
||
41 | */ |
||
42 | private $attributeDictionary; |
||
43 | |||
44 | /** |
||
45 | * @var InstitutionConfigurationOptionsService |
||
46 | */ |
||
47 | private $institutionConfigurationOptionsService; |
||
48 | |||
49 | /** |
||
50 | * @var LoggerInterface |
||
51 | */ |
||
52 | private $logger; |
||
53 | |||
54 | public function __construct( |
||
65 | |||
66 | /** |
||
67 | * @param SamlToken|TokenInterface $token |
||
68 | * @return TokenInterface|void |
||
69 | */ |
||
70 | public function authenticate(TokenInterface $token) |
||
71 | { |
||
72 | $translatedAssertion = $this->attributeDictionary->translate($token->assertion); |
||
73 | |||
74 | $nameId = $translatedAssertion->getNameID(); |
||
75 | $institution = $this->getSingleStringValue('schacHomeOrganization', $translatedAssertion); |
||
76 | |||
77 | $identity = $this->identityService->findByNameIdAndInstitution($nameId, $institution); |
||
78 | |||
79 | // if no identity can be found, we're done. |
||
80 | if ($identity === null) { |
||
81 | throw new BadCredentialsException( |
||
82 | 'Unable to find Identity matching the criteria. Has the identity been registered before?' |
||
83 | ); |
||
84 | } |
||
85 | |||
86 | $raCredentials = $this->identityService->getRaCredentials($identity); |
||
87 | |||
88 | // if no credentials can be found, we're done. |
||
89 | if (!$raCredentials) { |
||
90 | throw new BadCredentialsException( |
||
91 | 'The Identity is not registered as (S)RA(A) and therefor does not have access to this application' |
||
92 | ); |
||
93 | } |
||
94 | |||
95 | // determine the role based on the credentials given |
||
96 | $roles = []; |
||
97 | if ($raCredentials->isSraa) { |
||
98 | $roles[] = 'ROLE_SRAA'; |
||
99 | } |
||
100 | |||
101 | if ($raCredentials->isRaa) { |
||
102 | $roles[] = 'ROLE_RAA'; |
||
103 | } else { |
||
104 | $roles[] = 'ROLE_RA'; |
||
105 | } |
||
106 | |||
107 | $institutionConfigurationOptions = $this->institutionConfigurationOptionsService |
||
108 | ->getInstitutionConfigurationOptionsFor($identity->institution); |
||
109 | |||
110 | if ($institutionConfigurationOptions === null) { |
||
111 | throw new InconsistentStateException( |
||
112 | sprintf( |
||
113 | 'InstitutionConfigurationOptions for institution "%s" ' |
||
114 | . 'must exist but cannot be found after authenticating Identity "%s"', |
||
115 | $identity->institution, |
||
116 | $identity->id |
||
117 | ) |
||
118 | ); |
||
119 | } |
||
120 | |||
121 | // set the token |
||
122 | $authenticatedToken = new SamlToken($token->getLoa(), $roles, $institutionConfigurationOptions); |
||
123 | $authenticatedToken->setUser($identity); |
||
124 | |||
125 | return $authenticatedToken; |
||
126 | } |
||
127 | |||
128 | private function getSingleStringValue($attribute, AssertionAdapter $translatedAssertion) |
||
161 | |||
162 | public function supports(TokenInterface $token) |
||
166 | } |
||
167 |
Very long variable names usually make code harder to read. It is therefore recommended not to make variable names too verbose.