| 1 |  |  | <?php | 
            
                                                                                                            
                            
            
                                    
            
            
                | 2 |  |  |  | 
            
                                                                                                            
                            
            
                                    
            
            
                | 3 |  |  | /** | 
            
                                                                                                            
                            
            
                                    
            
            
                | 4 |  |  |  * This file is part of Blitz PHP framework. | 
            
                                                                                                            
                            
            
                                    
            
            
                | 5 |  |  |  * | 
            
                                                                                                            
                            
            
                                    
            
            
                | 6 |  |  |  * (c) 2022 Dimitri Sitchet Tomkeu <[email protected]> | 
            
                                                                                                            
                            
            
                                    
            
            
                | 7 |  |  |  * | 
            
                                                                                                            
                            
            
                                    
            
            
                | 8 |  |  |  * For the full copyright and license information, please view | 
            
                                                                                                            
                            
            
                                    
            
            
                | 9 |  |  |  * the LICENSE file that was distributed with this source code. | 
            
                                                                                                            
                            
            
                                    
            
            
                | 10 |  |  |  */ | 
            
                                                                                                            
                            
            
                                    
            
            
                | 11 |  |  |  | 
            
                                                                                                            
                            
            
                                    
            
            
                | 12 |  |  | namespace BlitzPHP\Middlewares; | 
            
                                                                                                            
                            
            
                                    
            
            
                | 13 |  |  |  | 
            
                                                                                                            
                            
            
                                    
            
            
                | 14 |  |  | use BlitzPHP\Container\Services; | 
            
                                                                                                            
                            
            
                                    
            
            
                | 15 |  |  | use BlitzPHP\Exceptions\RedirectException; | 
            
                                                                                                            
                            
            
                                    
            
            
                | 16 |  |  | use Psr\Http\Message\ResponseInterface; | 
            
                                                                                                            
                            
            
                                    
            
            
                | 17 |  |  | use Psr\Http\Message\ServerRequestInterface; | 
            
                                                                                                            
                            
            
                                    
            
            
                | 18 |  |  | use Psr\Http\Server\MiddlewareInterface; | 
            
                                                                                                            
                            
            
                                    
            
            
                | 19 |  |  | use Psr\Http\Server\RequestHandlerInterface; | 
            
                                                                                                            
                            
            
                                    
            
            
                | 20 |  |  |  | 
            
                                                                                                            
                            
            
                                    
            
            
                | 21 |  |  | class ForceHTTPS implements MiddlewareInterface | 
            
                                                                                                            
                            
            
                                    
            
            
                | 22 |  |  | { | 
            
                                                                                                            
                            
            
                                    
            
            
                | 23 |  |  |     /** | 
            
                                                                                                            
                            
            
                                    
            
            
                | 24 |  |  |      * Forcer l'accès au site sécurisé ? | 
            
                                                                                                            
                            
            
                                    
            
            
                | 25 |  |  |      * | 
            
                                                                                                            
                            
            
                                    
            
            
                | 26 |  |  |      * Si la valeur de configuration « forceGlobalSecureRequests » est vrai, imposera que toutes | 
            
                                                                                                            
                            
            
                                    
            
            
                | 27 |  |  |      * les demandes adressées à ce site soient effectuées via HTTPS. | 
            
                                                                                                            
                            
            
                                    
            
            
                | 28 |  |  |      * Redirigera l'utilisateur vers la page actuelle avec HTTPS, ainsi que définira l'en-tête | 
            
                                                                                                            
                            
            
                                    
            
            
                | 29 |  |  |      * HTTP Strict Transport Security (HSTS) pour les navigateurs qui le prennent en charge. | 
            
                                                                                                            
                                                                
            
                                    
            
            
                | 30 |  |  |      */ | 
            
                                                                        
                            
            
                                    
            
            
                | 31 |  |  |     public function process(ServerRequestInterface $request, RequestHandlerInterface $handler): ResponseInterface | 
            
                                                                        
                            
            
                                    
            
            
                | 32 |  |  |     { | 
            
                                                                        
                            
            
                                    
            
            
                | 33 |  |  |         if (config('app.force_global_secure_requests') !== true) { | 
                            
                    |  |  |  | 
                                                                                        
                                                                                     | 
            
                                                                        
                            
            
                                    
            
            
                | 34 |  |  |             return $handler->handle($request); | 
            
                                                                        
                            
            
                                    
            
            
                | 35 |  |  |         } | 
            
                                                                        
                            
            
                                    
            
            
                | 36 |  |  |  | 
            
                                                                        
                            
            
                                    
            
            
                | 37 |  |  |         try { | 
            
                                                                        
                            
            
                                    
            
            
                | 38 |  |  |             force_https(YEAR, $request, Services::redirection()); | 
            
                                                                        
                            
            
                                    
            
            
                | 39 |  |  |  | 
            
                                                                        
                            
            
                                    
            
            
                | 40 |  |  | 			return $handler->handle($request); | 
            
                                                                        
                            
            
                                    
            
            
                | 41 |  |  |         } catch (RedirectException $e) { | 
            
                                                                        
                            
            
                                    
            
            
                | 42 |  |  |             return $e->getResponse(); | 
            
                                                                                                            
                            
            
                                    
            
            
                | 43 |  |  |         } | 
            
                                                                                                            
                            
            
                                    
            
            
                | 44 |  |  |     } | 
            
                                                                                                            
                                                                
            
                                    
            
            
                | 45 |  |  | } | 
            
                                                        
            
                                    
            
            
                | 46 |  |  |  |