Passed
Push — develop ( 8f4078...6aa842 )
by nguereza
03:43
created

ApiAuthorizationMiddleware::__construct()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 3
Code Lines 0

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 1
eloc 0
nc 1
nop 1
dl 0
loc 3
rs 10
c 1
b 0
f 0
1
<?php
2
3
/**
4
 * Platine Framework
5
 *
6
 * Platine Framework is a lightweight, high-performance, simple and elegant
7
 * PHP Web framework
8
 *
9
 * This content is released under the MIT License (MIT)
10
 *
11
 * Copyright (c) 2020 Platine Framework
12
 *
13
 * Permission is hereby granted, free of charge, to any person obtaining a copy
14
 * of this software and associated documentation files (the "Software"), to deal
15
 * in the Software without restriction, including without limitation the rights
16
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
17
 * copies of the Software, and to permit persons to whom the Software is
18
 * furnished to do so, subject to the following conditions:
19
 *
20
 * The above copyright notice and this permission notice shall be included in all
21
 * copies or substantial portions of the Software.
22
 *
23
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
24
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
25
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
26
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
27
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
28
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
29
 * SOFTWARE.
30
 */
31
32
/**
33
 *  @file AuthorizationMiddleware.php
34
 *
35
 *  The API Authorization middleware class
36
 *
37
 *  @package    Platine\Framework\Auth\Middleware
38
 *  @author Platine Developers team
39
 *  @copyright  Copyright (c) 2020
40
 *  @license    http://opensource.org/licenses/MIT  MIT License
41
 *  @link   https://www.platine-php.com
42
 *  @version 1.0.0
43
 *  @filesource
44
 */
45
46
declare(strict_types=1);
47
48
namespace Platine\Framework\Auth\Middleware;
49
50
use Platine\Config\Config;
51
use Platine\Framework\Auth\AuthorizationInterface;
52
use Platine\Framework\Http\Response\RestResponse;
53
use Platine\Framework\Http\RouteHelper;
54
use Platine\Http\Handler\MiddlewareInterface;
55
use Platine\Http\Handler\RequestHandlerInterface;
56
use Platine\Http\ResponseInterface;
57
use Platine\Http\ServerRequestInterface;
58
use Platine\Route\Route;
59
60
/**
61
 * @class ApiAuthorizationMiddleware
62
 * @package Platine\Framework\Auth\Middleware
63
 * @template T
64
 */
65
class ApiAuthorizationMiddleware implements MiddlewareInterface
66
{
67
    /**
68
     * Create new instance
69
     * @param AuthorizationInterface $authorization
70
     */
71
    public function __construct(
72
        protected AuthorizationInterface $authorization,
73
    ) {
74
    }
75
76
    /**
77
     * {@inheritdoc}
78
     */
79
    public function process(
80
        ServerRequestInterface $request,
81
        RequestHandlerInterface $handler
82
    ): ResponseInterface {
83
        //If no route has been match no need check for authorization
84
        /** @var Route|null $route */
85
        $route = $request->getAttribute(Route::class);
86
        if ($route === null) {
87
            return $handler->handle($request);
88
        }
89
90
        $permission = $route->getAttribute('permission');
91
92
        if (empty($permission)) {
93
            return $handler->handle($request);
94
        }
95
96
        if ($this->authorization->isGranted($permission) === false) {
97
            return new RestResponse(
98
                [],
99
                [],
100
                false,
101
                4030,
102
                'Permission denied for this user',
103
                403
104
            );
105
        }
106
107
        return $handler->handle($request);
108
    }
109
}
110