Passed
Push — develop ( 36c2b4...1d782e )
by nguereza
03:02
created

HMAC   A

Complexity

Total Complexity 7

Size/Duplication

Total Lines 77
Duplicated Lines 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
eloc 16
c 1
b 0
f 0
dl 0
loc 77
rs 10
wmc 7

6 Methods

Rating   Name   Duplication   Size   Complexity  
A verify() 0 5 1
A hashEquals() 0 3 1
A getSignatureAlgo() 0 3 1
A getTokenAlgoName() 0 3 1
A sign() 0 3 1
A __construct() 0 12 2
1
<?php
2
3
/**
4
 * Platine Framework
5
 *
6
 * Platine Framework is a lightweight, high-performance, simple and elegant PHP
7
 * Web framework
8
 *
9
 * This content is released under the MIT License (MIT)
10
 *
11
 * Copyright (c) 2020 Platine Framework
12
 *
13
 * Permission is hereby granted, free of charge, to any person obtaining a copy
14
 * of this software and associated documentation files (the "Software"), to deal
15
 * in the Software without restriction, including without limitation the rights
16
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
17
 * copies of the Software, and to permit persons to whom the Software is
18
 * furnished to do so, subject to the following conditions:
19
 *
20
 * The above copyright notice and this permission notice shall be included in all
21
 * copies or substantial portions of the Software.
22
 *
23
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
24
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
25
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
26
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
27
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
28
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
29
 * SOFTWARE.
30
 */
31
32
/**
33
 *  @file HMAC.php
34
 *
35
 *  The Signer using HMAC
36
 *
37
 *  @package    Platine\Framework\Security\JWT\Signer
38
 *  @author Platine Developers team
39
 *  @copyright  Copyright (c) 2020
40
 *  @license    http://opensource.org/licenses/MIT  MIT License
41
 *  @link   http://www.iacademy.cf
42
 *  @version 1.0.0
43
 *  @filesource
44
 */
45
46
declare(strict_types=1);
47
48
namespace Platine\Framework\Security\JWT\Signer;
49
50
use Platine\Config\Config;
51
use Platine\Framework\Security\JWT\Exception\InvalidAlgorithmException;
52
use Platine\Framework\Security\JWT\SignerInterface;
53
54
/**
55
 * @class HMAC
56
 * @package Platine\Framework\Security\JWT\Signer
57
 * @template T
58
 */
59
class HMAC implements SignerInterface
60
{
61
62
    /**
63
     * The configuration instance
64
     * @var Config<T>
65
     */
66
    protected Config $config;
67
68
    /**
69
     * The algorithm to use
70
     * @var string
71
     */
72
    protected string $algo;
73
74
    /**
75
     * Create new instance
76
     * @param Config<T> $config
77
     */
78
    public function __construct(Config $config)
79
    {
80
        $this->config = $config;
81
        $algo = $config->get('api.sign.hmac.signature_algo', '');
82
        if (!in_array($algo, hash_hmac_algos())) {
83
            throw new InvalidAlgorithmException(sprintf(
84
                'Invalid HMAC algorithm [%s]',
85
                $algo
86
            ));
87
        }
88
89
        $this->algo = $algo;
90
    }
91
92
93
    /**
94
     * {@inheritdoc}
95
     */
96
    public function sign(string $data, string $key): string
97
    {
98
        return hash_hmac($this->algo, $data, $key, true);
99
    }
100
101
    /**
102
     * {@inheritdoc}
103
     */
104
    public function verify(string $key, string $signature, string $data): bool
105
    {
106
        $signed = $this->sign($data, $key);
107
108
        return $this->hashEquals($signed, $signature);
109
    }
110
111
    /**
112
     * {@inheritdoc}
113
     */
114
    public function getSignatureAlgo(): string
115
    {
116
        return $this->algo;
117
    }
118
119
    /**
120
     * {@inheritdoc}
121
     */
122
    public function getTokenAlgoName(): string
123
    {
124
        return $this->config->get('api.sign.hmac.token_header_algo', '');
125
    }
126
127
    /**
128
     * Test if two hash is equals
129
     * @param string $signature
130
     * @param string $data
131
     * @return bool
132
     */
133
    protected function hashEquals(string $signature, string $data): bool
134
    {
135
        return hash_equals($signature, $data);
136
    }
137
}
138