SecureCookie   A
last analyzed

Complexity

Total Complexity 3

Size/Duplication

Total Lines 28
Duplicated Lines 0 %

Test Coverage

Coverage 0%

Importance

Changes 0
Metric Value
dl 0
loc 28
ccs 0
cts 8
cp 0
rs 10
c 0
b 0
f 0
wmc 3

1 Method

Rating   Name   Duplication   Size   Complexity  
A encryptKey() 0 17 3
1
<?php namespace Comodojo\Cookies;
2
3
/**
4
 * AES-encrypted cookie using client-specific key
5
 *
6
 * @package     Comodojo Spare Parts
7
 * @author      Marco Giovinazzi <[email protected]>
8
 * @license     MIT
9
 *
10
 * LICENSE:
11
 *
12
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
13
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
14
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
15
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
16
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
17
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
18
 * THE SOFTWARE.
19
 */
20
21
class SecureCookie extends EncryptedCookie {
22
23
    /**
24
     * Create a client-specific key using provided key,
25
     * the client remote address and (in case) the value of
26
     * HTTP_X_FORWARDED_FOR header
27
     *
28
     * @param string $key
29
     *
30
     * @return string
31
     */
32
    protected static function encryptKey($key) {
33
34
        if ( isset($_SERVER['REMOTE_ADDR']) ) {
35
36
            $client_hash = md5($_SERVER['REMOTE_ADDR'].(isset($_SERVER['HTTP_X_FORWARDED_FOR']) ? $_SERVER['HTTP_X_FORWARDED_FOR'] : ''), true);
37
38
            $server_hash = md5($key, true);
39
40
            $cookie_key = $client_hash.$server_hash;
41
42
        } else {
43
44
            $cookie_key = hash('sha256', $key);
45
46
        }
47
48
        return $cookie_key;
49
50
    }
51
52
}
53