Completed
Push — master ( 2d24bc...d92872 )
by Joschi
03:47
created

Authentication   A

Complexity

Total Complexity 6

Size/Duplication

Total Lines 60
Duplicated Lines 0 %

Coupling/Cohesion

Components 0
Dependencies 3

Test Coverage

Coverage 30.76%

Importance

Changes 2
Bugs 0 Features 0
Metric Value
wmc 6
c 2
b 0
f 0
lcom 0
cbo 3
dl 0
loc 60
ccs 4
cts 13
cp 0.3076
rs 10

1 Method

Rating   Name   Duplication   Size   Complexity  
B __invoke() 0 27 6
1
<?php
2
3
/**
4
 * apparat-server
5
 *
6
 * @category    Apparat
7
 * @package     Apparat\Server
8
 * @subpackage  Apparat\Server\Infrastructure
9
 * @author      Joschi Kuphal <[email protected]> / @jkphl
10
 * @copyright   Copyright © 2016 Joschi Kuphal <[email protected]> / @jkphl
11
 * @license     http://opensource.org/licenses/MIT The MIT License (MIT)
12
 */
13
14
/***********************************************************************************
15
 *  The MIT License (MIT)
16
 *
17
 *  Copyright © 2016 Joschi Kuphal <[email protected]> / @jkphl
18
 *
19
 *  Permission is hereby granted, free of charge, to any person obtaining a copy of
20
 *  this software and associated documentation files (the "Software"), to deal in
21
 *  the Software without restriction, including without limitation the rights to
22
 *  use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
23
 *  the Software, and to permit persons to whom the Software is furnished to do so,
24
 *  subject to the following conditions:
25
 *
26
 *  The above copyright notice and this permission notice shall be included in all
27
 *  copies or substantial portions of the Software.
28
 *
29
 *  THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
30
 *  IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
31
 *  FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
32
 *  COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
33
 *  IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
34
 *  CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
35
 ***********************************************************************************/
36
37
namespace Apparat\Server\Infrastructure\Rule;
38
39
use Apparat\Server\Ports\Authenticator\AuthenticatorInterface;
40
use Apparat\Server\Ports\Authenticator\InvalidArgumentException;
41
use Aura\Router\Route;
42
use Aura\Router\Rule\RuleInterface;
43
use Psr\Http\Message\ServerRequestInterface;
44
45
/**
46
 * Authentication rule
47
 *
48
 * @package Apparat\Server
49
 * @subpackage Apparat\Server\Infrastructure
50
 */
51
class Authentication implements RuleInterface
52
{
53
    /**
54
     * Basic authentication
55
     *
56
     * @var string
57
     */
58
    const BASIC = 'basic';
59
    /**
60
     * OAuth2 Bearer authentication
61
     *
62
     * @var string
63
     */
64
    const BEARER = 'bearer';
65
    /**
66
     * Supported authentication types
67
     *
68
     * @var array
69
     */
70
    protected static $authenticationTypes = [
71
        self::BASIC => true,
72
        self::BEARER => true,
73
    ];
74
75
    /**
76
     * Check if the request matches the required authentication state
77
     *
78
     * @param ServerRequestInterface $request HTTP request
79
     * @param Route $route Route
80
     * @return boolean The request matches the required authentication state
81
     * @throw InvalidArgumentException If the provided authenticator is invalid
82
     */
83 77
    public function __invoke(ServerRequestInterface $request, Route $route)
84
    {
85
        // If no authentication is required for this route
86 77
        $auth = $route->auth;
87 77
        if (!is_array($auth) || !count($auth = array_intersect_key($auth, self::$authenticationTypes))) {
88 77
            return true;
89
        }
90
91
        // Run through all authentication possibilities
92
        foreach ($auth as $type => $authenticator) {
93
            // If the provided authenticator is invalid
94
            if (!($authenticator instanceof AuthenticatorInterface)) {
95
                throw new InvalidArgumentException(
96
                    sprintf('Invalid authenticator for type "%s"', $type),
97
                    InvalidArgumentException::INVALID_AUTHENTICATOR
98
                );
99
            }
100
101
            // Try to authenticate the request
102
            if ($authenticator->authenticate($request) === true) {
103
                return true;
104
            }
105
        }
106
107
        // Request is not authenticated
108
        return false;
109
    }
110
}
111