Passed
Push — develop ( cb5f9f...78e2ce )
by nguereza
05:02
created

CsrfManager::getConfigValue()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 5
Code Lines 2

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 1
eloc 2
c 1
b 0
f 0
nc 1
nop 1
dl 0
loc 5
rs 10
1
<?php
2
3
/**
4
 * Platine Framework
5
 *
6
 * Platine Framework is a lightweight, high-performance, simple and elegant PHP
7
 * Web framework
8
 *
9
 * This content is released under the MIT License (MIT)
10
 *
11
 * Copyright (c) 2020 Platine Framework
12
 *
13
 * Permission is hereby granted, free of charge, to any person obtaining a copy
14
 * of this software and associated documentation files (the "Software"), to deal
15
 * in the Software without restriction, including without limitation the rights
16
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
17
 * copies of the Software, and to permit persons to whom the Software is
18
 * furnished to do so, subject to the following conditions:
19
 *
20
 * The above copyright notice and this permission notice shall be included in all
21
 * copies or substantial portions of the Software.
22
 *
23
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
24
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
25
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
26
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
27
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
28
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
29
 * SOFTWARE.
30
 */
31
32
/**
33
 *  @file CsrfManager.php
34
 *
35
 *  The CSRF manager class
36
 *
37
 *  @package    Platine\Framework\Security\Csrf
38
 *  @author Platine Developers team
39
 *  @copyright  Copyright (c) 2020
40
 *  @license    http://opensource.org/licenses/MIT  MIT License
41
 *  @link   https://www.platine-php.com
42
 *  @version 1.0.0
43
 *  @filesource
44
 */
45
46
declare(strict_types=1);
47
48
namespace Platine\Framework\Security\Csrf;
49
50
use Platine\Config\Config;
51
use Platine\Framework\Http\RequestData;
52
use Platine\Framework\Security\Csrf\CsrfStorageInterface;
53
use Platine\Http\ServerRequestInterface;
54
use Platine\Stdlib\Helper\Str;
55
56
/**
57
 * @class CsrfManager
58
 * @package Platine\Framework\Security\Csrf
59
 */
60
class CsrfManager
61
{
62
    /**
63
     * The application configuration class
64
     * @var Config
65
     */
66
    protected Config $config;
67
68
    /**
69
     * The storage to be used
70
     * @var CsrfStorageInterface
71
     */
72
    protected CsrfStorageInterface $storage;
73
74
    /**
75
     * Whether return need generate token per request or not
76
     * @var bool
77
     */
78
    protected bool $unique = false;
79
80
    /**
81
     * Create new instance
82
     * @param Config $config
83
     * @param CsrfStorageInterface|null $storage
84
     */
85
    public function __construct(
86
        Config $config,
87
        ?CsrfStorageInterface $storage = null
88
    ) {
89
        $this->config = $config;
90
        $this->storage = $storage ??  new CsrfNullStorage();
0 ignored issues
show
Bug introduced by
The type Platine\Framework\Security\Csrf\CsrfNullStorage was not found. Maybe you did not declare it correctly or list all dependencies?

The issue could also be caused by a filter entry in the build configuration. If the path has been excluded in your configuration, e.g. excluded_paths: ["lib/*"], you can move it to the dependency path list as follows:

filter:
    dependency_paths: ["lib/*"]

For further information see https://scrutinizer-ci.com/docs/tools/php/php-scrutinizer/#list-dependency-paths

Loading history...
91
    }
92
93
    /**
94
     * Validate the token
95
     * @param ServerRequestInterface $request
96
     * @param string|null $key
97
     * @return bool
98
     */
99
    public function validate(ServerRequestInterface $request, ?string $key = null): bool
100
    {
101
        if ($key === null) {
102
            $key = $this->getConfigValue('key');
103
        }
104
105
        $data = $this->storage->get($key);
106
        if ($data === null || $data['expire'] <= time()) {
107
            return false;
108
        }
109
110
        $param = new RequestData($request);
111
        $token = $param->post($key);
112
        if ($token === null) {
113
            $token = $param->get($key);
114
        }
115
116
        if ($token === null || $token !== $data['value']) {
117
            return false;
118
        }
119
120
        if ($this->unique === false) {
121
            $this->storage->delete($key);
122
        }
123
124
        return true;
125
    }
126
127
    /**
128
     * Return the token
129
     * @param string|null $key
130
     * @return string
131
     */
132
    public function getToken(?string $key = null): string
133
    {
134
        if ($key === null) {
135
            $key = $this->getConfigValue('key');
136
        }
137
138
        $data = $this->storage->get($key);
139
        if ($data === null) {
140
            // Generate
141
            $value = sha1(Str::randomToken(24));
142
            $expire = $this->getConfigValue('expire') ?? 300;
143
            $expireTime = time() + $expire;
144
145
            $data = [
146
                'expire' => $expireTime,
147
                'value' => $value,
148
            ];
149
150
            $this->storage->set($key, $data);
151
        }
152
153
        return $data['value'];
154
    }
155
156
    /**
157
     * Clear all CSRF data from storage
158
     * @return void
159
     */
160
    public function clear(): void
161
    {
162
        $this->storage->clear();
163
    }
164
165
    /**
166
     *
167
     * @param bool $status
168
     * @return $this
169
     */
170
    public function unique(bool $status = true): self
171
    {
172
        $this->unique = $status;
173
174
        return $this;
175
    }
176
177
    /**
178
     * Return the CSRF configuration value
179
     * @param string $key
180
     * @return mixed
181
     */
182
    private function getConfigValue(string $key)
183
    {
184
        $config = $this->config->get('security.csrf', []);
185
186
        return $config[$key] ?? null;
187
    }
188
}
189