1 | <?php |
||
34 | class DefaultTokenProvider implements IProvider { |
||
35 | |||
36 | /** @var DefaultTokenMapper */ |
||
37 | private $mapper; |
||
38 | |||
39 | /** @var ICrypto */ |
||
40 | private $crypto; |
||
41 | |||
42 | /** @var IConfig */ |
||
43 | private $config; |
||
44 | |||
45 | /** @var ILogger $logger */ |
||
46 | private $logger; |
||
47 | |||
48 | /** @var ITimeFactory $time */ |
||
49 | private $time; |
||
50 | |||
51 | /** |
||
52 | * @param DefaultTokenMapper $mapper |
||
53 | * @param ICrypto $crypto |
||
54 | * @param IConfig $config |
||
55 | * @param ILogger $logger |
||
56 | * @param ITimeFactory $time |
||
57 | */ |
||
58 | public function __construct(DefaultTokenMapper $mapper, ICrypto $crypto, IConfig $config, ILogger $logger, ITimeFactory $time) { |
||
65 | |||
66 | /** |
||
67 | * Create and persist a new token |
||
68 | * |
||
69 | * @param string $token |
||
70 | * @param string $uid |
||
71 | * @param string $loginName |
||
72 | * @param string|null $password |
||
73 | * @param string $name |
||
74 | * @param int $type token type |
||
75 | * @return IToken |
||
76 | */ |
||
77 | public function generateToken($token, $uid, $loginName, $password, $name, $type = IToken::TEMPORARY_TOKEN) { |
||
78 | $dbToken = new DefaultToken(); |
||
79 | $dbToken->setUid($uid); |
||
80 | $dbToken->setLoginName($loginName); |
||
81 | if (!is_null($password)) { |
||
82 | $dbToken->setPassword($this->encryptPassword($password, $token)); |
||
83 | } |
||
84 | $dbToken->setName($name); |
||
85 | $dbToken->setToken($this->hashToken($token)); |
||
86 | $dbToken->setType($type); |
||
87 | $dbToken->setLastActivity($this->time->getTime()); |
||
88 | |||
89 | $this->mapper->insert($dbToken); |
||
90 | |||
91 | return $dbToken; |
||
92 | } |
||
93 | |||
94 | /** |
||
95 | * Update token activity timestamp |
||
96 | * |
||
97 | * @throws InvalidTokenException |
||
98 | * @param IToken $token |
||
99 | */ |
||
100 | public function updateToken(IToken $token) { |
||
109 | |||
110 | /** |
||
111 | * Get all token of a user |
||
112 | * |
||
113 | * The provider may limit the number of result rows in case of an abuse |
||
114 | * where a high number of (session) tokens is generated |
||
115 | * |
||
116 | * @param IUser $user |
||
117 | * @return IToken[] |
||
118 | */ |
||
119 | public function getTokenByUser(IUser $user) { |
||
122 | |||
123 | /** |
||
124 | * Get a token by token id |
||
125 | * |
||
126 | * @param string $tokenId |
||
127 | * @throws InvalidTokenException |
||
128 | * @return DefaultToken |
||
129 | */ |
||
130 | public function getToken($tokenId) { |
||
137 | |||
138 | /** |
||
139 | * @param IToken $savedToken |
||
140 | * @param string $tokenId session token |
||
141 | * @throws InvalidTokenException |
||
142 | * @throws PasswordlessTokenException |
||
143 | * @return string |
||
144 | */ |
||
145 | public function getPassword(IToken $savedToken, $tokenId) { |
||
152 | |||
153 | /** |
||
154 | * Encrypt and set the password of the given token |
||
155 | * |
||
156 | * @param IToken $token |
||
157 | * @param string $tokenId |
||
158 | * @param string $password |
||
159 | * @throws InvalidTokenException |
||
160 | */ |
||
161 | public function setPassword(IToken $token, $tokenId, $password) { |
||
169 | |||
170 | /** |
||
171 | * Invalidate (delete) the given session token |
||
172 | * |
||
173 | * @param string $token |
||
174 | */ |
||
175 | public function invalidateToken($token) { |
||
178 | |||
179 | /** |
||
180 | * Invalidate (delete) the given token |
||
181 | * |
||
182 | * @param IUser $user |
||
183 | * @param int $id |
||
184 | */ |
||
185 | public function invalidateTokenById(IUser $user, $id) { |
||
188 | |||
189 | /** |
||
190 | * Invalidate (delete) old session tokens |
||
191 | */ |
||
192 | public function invalidateOldTokens() { |
||
197 | |||
198 | /** |
||
199 | * @param string $token |
||
200 | * @throws InvalidTokenException |
||
201 | * @return DefaultToken user UID |
||
202 | */ |
||
203 | public function validateToken($token) { |
||
212 | |||
213 | /** |
||
214 | * @param string $token |
||
215 | * @return string |
||
216 | */ |
||
217 | private function hashToken($token) { |
||
221 | |||
222 | /** |
||
223 | * Encrypt the given password |
||
224 | * |
||
225 | * The token is used as key |
||
226 | * |
||
227 | * @param string $password |
||
228 | * @param string $token |
||
229 | * @return string encrypted password |
||
230 | */ |
||
231 | private function encryptPassword($password, $token) { |
||
235 | |||
236 | /** |
||
237 | * Decrypt the given password |
||
238 | * |
||
239 | * The token is used as key |
||
240 | * |
||
241 | * @param string $password |
||
242 | * @param string $token |
||
243 | * @throws InvalidTokenException |
||
244 | * @return string the decrypted key |
||
245 | */ |
||
246 | private function decryptPassword($password, $token) { |
||
256 | |||
257 | } |
||
258 |