1 | <?php |
||
13 | final class CsrfErrorResponseMiddleware |
||
14 | { |
||
15 | /** |
||
16 | * @var CsrfTokenGeneratorInterface |
||
17 | */ |
||
18 | private $csrfTokenGenerator; |
||
19 | |||
20 | /** |
||
21 | * @var SessionInterface |
||
22 | */ |
||
23 | private $session; |
||
24 | |||
25 | const CSRF_KEY = 'csrf'; |
||
26 | |||
27 | /** |
||
28 | * @var CsrfErrorHandlerInterface |
||
29 | */ |
||
30 | private $errorResponseHandler; |
||
31 | |||
32 | /** |
||
33 | * @var LoggerInterface |
||
34 | */ |
||
35 | private $logger; |
||
36 | |||
37 | const EXCEPTION_STATUS = 424; |
||
38 | |||
39 | const EXCEPTION_MISSING_IN_SESSION = 'Csrf token is missing within session'; |
||
40 | const EXCEPTION_MISSING_IN_BODY = 'Csrf token is missing within body'; |
||
41 | const EXCEPTION_IS_NOT_SAME = 'Csrf token within body is not the same as in session'; |
||
42 | |||
43 | /** |
||
44 | * @param CsrfTokenGeneratorInterface $csrfTokenGenerator |
||
45 | * @param SessionInterface $session |
||
46 | * @param CsrfErrorHandlerInterface $errorResponseHandler |
||
47 | * @param LoggerInterface|null $logger |
||
48 | */ |
||
49 | 6 | public function __construct( |
|
60 | |||
61 | /** |
||
62 | * @param Request $request |
||
63 | * @param Response $response |
||
64 | * @param callable $next |
||
65 | * |
||
66 | * @return Response |
||
67 | */ |
||
68 | 6 | public function __invoke(Request $request, Response $response, callable $next = null) |
|
88 | |||
89 | /** |
||
90 | * @param Request $request |
||
91 | * @param Response $response |
||
92 | * |
||
93 | * @return Response|null |
||
94 | */ |
||
95 | 4 | private function checkCsrf(Request $request, Response $response) |
|
113 | |||
114 | /** |
||
115 | * @param Request $request |
||
116 | * @param Response $response |
||
117 | * @param string $reasonPhrase |
||
118 | * |
||
119 | * @return Response |
||
120 | */ |
||
121 | 3 | private function errorResponse(Request $request, Response $response, string $reasonPhrase) |
|
132 | } |
||
133 |