AbstractBearer   A
last analyzed

Complexity

Total Complexity 11

Size/Duplication

Total Lines 75
Duplicated Lines 0 %

Coupling/Cohesion

Components 1
Dependencies 1

Test Coverage

Coverage 100%

Importance

Changes 0
Metric Value
wmc 11
lcom 1
cbo 1
dl 0
loc 75
ccs 21
cts 21
cp 1
rs 10
c 0
b 0
f 0

5 Methods

Rating   Name   Duplication   Size   Complexity  
A authenticate() 0 6 3
A authenticateHeader() 0 18 4
verifyToken() 0 1 ?
A authenticateBody() 0 6 2
A authenticateQuery() 0 6 2
1
<?php
2
3
/**
4
 * apparat-server
5
 *
6
 * @category    Apparat
7
 * @package     Apparat\Server
8
 * @subpackage  Apparat\Server\Ports
9
 * @author      Joschi Kuphal <[email protected]> / @jkphl
10
 * @copyright   Copyright © 2016 Joschi Kuphal <[email protected]> / @jkphl
11
 * @license     http://opensource.org/licenses/MIT The MIT License (MIT)
12
 */
13
14
/***********************************************************************************
15
 *  The MIT License (MIT)
16
 *
17
 *  Copyright © 2016 Joschi Kuphal <[email protected]> / @jkphl
18
 *
19
 *  Permission is hereby granted, free of charge, to any person obtaining a copy of
20
 *  this software and associated documentation files (the "Software"), to deal in
21
 *  the Software without restriction, including without limitation the rights to
22
 *  use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
23
 *  the Software, and to permit persons to whom the Software is furnished to do so,
24
 *  subject to the following conditions:
25
 *
26
 *  The above copyright notice and this permission notice shall be included in all
27
 *  copies or substantial portions of the Software.
28
 *
29
 *  THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
30
 *  IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
31
 *  FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
32
 *  COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
33
 *  IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
34
 *  CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
35
 ***********************************************************************************/
36
37
namespace Apparat\Server\Ports\Authenticator;
38
39
use Psr\Http\Message\ServerRequestInterface;
40
41
/**
42
 * Abstract bearer authenticator
43
 *
44
 * @package Apparat\Server
45
 * @subpackage Apparat\Server\Ports
46
 * @see https://tools.ietf.org/html/rfc6750#section-2
47
 */
48
abstract class AbstractBearer implements AuthenticatorInterface
49
{
50
    /**
51
     * Authenticate a request
52
     *
53
     * @param ServerRequestInterface $request Request
54
     * @return boolean Request is authenticated
55
     * @see https://quill.p3k.io/creating-a-micropub-endpoint#verifying-access-tokens
56
     */
57 1
    public function authenticate(ServerRequestInterface $request)
58
    {
59 1
        return $this->authenticateHeader($request)
60 1
        || $this->authenticateBody($request)
61 1
        || $this->authenticateQuery($request);
62
    }
63
64
    /**
65
     * Authenticate with an "Authorization" header
66
     *
67
     * @param ServerRequestInterface $request Request
68
     * @return bool Request is valid
69
     */
70 1
    protected function authenticateHeader(ServerRequestInterface $request)
71
    {
72
        // Run through all "Authorization" headers
73 1
        foreach ($request->getHeader('Authorization') as $authHeader) {
0 ignored issues
show
Coding Style introduced by
Blank line found at start of control structure
Loading history...
74
75
            // If this is supposed to be a bearer token
76 1
            if (!strncmp(strtolower($authHeader), 'bearer', 6)) {
77 1
                $bearerToken = preg_split('%\s+%', $authHeader);
78
79
                // If there is really a bearer token
80 1
                if (count($bearerToken) > 1) {
81 1
                    return $this->verifyToken($bearerToken[1]);
82
                }
83 1
            }
84 1
        }
85
86 1
        return false;
87
    }
88
89
    /**
90
     * Verify the validity of the bearer token
91
     *
92
     * @param string $token Bearer token
93
     * @return boolean The bearer token is valid
94
     */
95
    abstract protected function verifyToken($token);
96
97
    /**
98
     * Authenticate with an "access_token" body parameter
99
     *
100
     * @param ServerRequestInterface $request Request
101
     * @return bool Request is valid
102
     */
103 1
    protected function authenticateBody(ServerRequestInterface $request)
104
    {
105 1
        $bodyParameters = (array)$request->getParsedBody();
106 1
        return array_key_exists('access_token', $bodyParameters) ?
107 1
            $this->verifyToken($bodyParameters['access_token']) : false;
108
    }
109
110
    /**
111
     * Authenticate with an "access_token" query parameter
112
     *
113
     * @param ServerRequestInterface $request Request
114
     * @return bool Request is valid
115
     */
116 1
    protected function authenticateQuery(ServerRequestInterface $request)
117
    {
118 1
        $queryParameters = (array)$request->getQueryParams();
119 1
        return array_key_exists('access_token', $queryParameters) ?
120 1
            $this->verifyToken($queryParameters['access_token']) : false;
121
    }
122
}
123