1 | <?php |
||
19 | class CsrfGuard |
||
20 | { |
||
21 | /** |
||
22 | * @var array Php session data from superglobal. |
||
23 | */ |
||
24 | private $session; |
||
25 | |||
26 | /** |
||
27 | * @var int Max number of tokens stored in session. |
||
28 | */ |
||
29 | private $maxStorage; |
||
30 | |||
31 | /** |
||
32 | * @var int Rapresent the lenght of the token in bytes. |
||
33 | */ |
||
34 | private $tokenStrength; |
||
35 | |||
36 | /** |
||
37 | * __construct. |
||
38 | * |
||
39 | * Class constructor. |
||
40 | * |
||
41 | * @param int $maxStorage Max number of tokens stored in session, work as |
||
42 | * FIFO data structure, when maximun capacity is |
||
43 | * reached, oldest token be dequeued from storage. |
||
44 | * @param int $tokenStrength Rapresent the lenght of the token in bytes. |
||
45 | */ |
||
46 | 22 | public function __construct(int $maxStorage, int $tokenStrength) |
|
61 | |||
62 | /** |
||
63 | * dequeue. |
||
64 | * |
||
65 | * Limit number of token stored in session. |
||
66 | */ |
||
67 | 20 | private function dequeue(array &$array) |
|
76 | |||
77 | /** |
||
78 | * getToken. |
||
79 | * |
||
80 | * Return csrf token as array. |
||
81 | * |
||
82 | * @return array |
||
83 | */ |
||
84 | 17 | public function getToken() : array |
|
100 | |||
101 | /** |
||
102 | * getTimedToken. |
||
103 | * |
||
104 | * Return timed csrf token as array. |
||
105 | * |
||
106 | * @param int $ttl Time to live for the token. |
||
107 | * |
||
108 | * @return array |
||
109 | */ |
||
110 | 3 | public function getTimedToken(int $ttl) : array |
|
123 | |||
124 | /** |
||
125 | * generateToken. |
||
126 | * |
||
127 | * Generate a random token. |
||
128 | * |
||
129 | * @return array |
||
130 | */ |
||
131 | 20 | private function generateToken() : array |
|
138 | |||
139 | /** |
||
140 | * getHiddenInput. |
||
141 | * |
||
142 | * Return csrf token as hidden input form. |
||
143 | * |
||
144 | * @return string |
||
145 | * |
||
146 | * @deprecated since version 1.1.0 |
||
147 | */ |
||
148 | 1 | public function getHiddenInput() : string |
|
154 | |||
155 | /** |
||
156 | * validate. |
||
157 | * |
||
158 | * Validate a csrf token or a csrf timed token. |
||
159 | * |
||
160 | * @param array $requestData From request or from superglobal variables $_POST, |
||
161 | * $_GET, $_REQUEST and $_COOKIE. |
||
162 | * |
||
163 | * @return bool |
||
164 | */ |
||
165 | 3 | public function validate(array $requestData) : bool |
|
173 | |||
174 | /** |
||
175 | * doChecks. |
||
176 | * |
||
177 | * Tests for valid token. |
||
178 | * |
||
179 | * @param string $value |
||
180 | * @param string $key |
||
181 | * |
||
182 | * @return bool |
||
183 | */ |
||
184 | 3 | private function doChecks(string $value, string $key) : bool |
|
190 | |||
191 | /** |
||
192 | * tokenIsValid. |
||
193 | * |
||
194 | * Check if token is valid |
||
195 | * |
||
196 | * @param array $tokens |
||
197 | * @param string $value |
||
198 | * @return bool |
||
199 | */ |
||
200 | 3 | private function tokenIsValid(array &$tokens, string &$value, string &$key) : bool |
|
214 | |||
215 | /** |
||
216 | * tokenIsExiperd. |
||
217 | * |
||
218 | * Check if timed token is expired. |
||
219 | * |
||
220 | * @param array $tokens |
||
221 | * @return bool |
||
222 | */ |
||
223 | 3 | private function tokenIsExiperd(array &$tokens, string &$key) : bool |
|
232 | } |
||
233 |