| Total Complexity | 12 |
| Total Lines | 64 |
| Duplicated Lines | 0 % |
| Coverage | 0% |
| Changes | 0 | ||
| 1 | <?php |
||
| 24 | class BasicAuthProcessor implements AuthProcessor |
||
| 25 | { |
||
| 26 | public function authenticate(AuthBackend $backend, string $credentials): ?object |
||
| 27 | { |
||
| 28 | try { |
||
| 29 | return $backend( |
||
| 30 | $this->getTokenPrefix(), |
||
| 31 | join(':', $this->decodeCredentials($this->extractCredentials($credentials))) |
||
| 32 | ); |
||
| 33 | } catch (HTTPError $e) { |
||
| 34 | throw $e; |
||
| 35 | } catch (Throwable $e) { |
||
| 36 | throw new HTTPUnauthorized( |
||
| 37 | title: __('Authorization failed'), |
||
| 38 | detail: $e->getMessage() |
||
| 39 | ); |
||
| 40 | } |
||
| 41 | } |
||
| 42 | |||
| 43 | public function getTokenPrefix(): string |
||
| 46 | } |
||
| 47 | |||
| 48 | protected function extractCredentials(string $credentials): string |
||
| 49 | { |
||
| 50 | $credentials = trim($credentials); |
||
| 51 | empty($credentials) and throw new HTTPUnauthorized( |
||
| 52 | title: __('Invalid authorization credentials'), |
||
| 53 | detail: __('The authorization header is missing'), |
||
| 54 | type: 'https://kodedphp.github.io/auth/header', |
||
| 55 | headers: ['WWW-Authenticate' => $this->getTokenPrefix()] |
||
| 56 | ); |
||
| 57 | $parts = mb_split('\s', $credentials); |
||
| 58 | |||
| 59 | (strtolower($parts[0]) !== strtolower($this->getTokenPrefix())) and throw new HTTPUnauthorized( |
||
| 60 | title: __('Authorization failed'), |
||
| 61 | detail: __('Authorization header must start with %s', [$this->getTokenPrefix()]), |
||
| 62 | type: 'https://kodedphp.github.io/auth/format', |
||
| 63 | headers: ['WWW-Authenticate' => $this->getTokenPrefix()] |
||
| 64 | ); |
||
| 65 | 1 === count($parts) and throw new HTTPUnauthorized( |
||
| 66 | title: __('Authorization failed'), |
||
| 67 | detail: __('Missing authorization value'), |
||
| 68 | type: 'https://kodedphp.github.io/auth/value', |
||
| 69 | headers: ['WWW-Authenticate' => $this->getTokenPrefix()] |
||
| 70 | ); |
||
| 71 | 2 < count($parts) and throw new HTTPUnauthorized( |
||
| 72 | title: __('Authorization failed'), |
||
| 73 | detail: __('Authorization header contains extra values'), |
||
| 74 | type: 'https://kodedphp.github.io/auth/format' |
||
| 75 | ); |
||
| 76 | return $parts[1]; |
||
| 77 | } |
||
| 78 | |||
| 79 | private function decodeCredentials(string $secret): array |
||
| 88 | } |
||
| 89 | } |
||
| 90 |