Test Failed
Push — develop ( 5ff630...7f862e )
by nguereza
03:35
created

AuthorizationMiddleware::isAllowed()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 5
Code Lines 2

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 1
eloc 2
c 1
b 0
f 0
nc 1
nop 1
dl 0
loc 5
rs 10
1
<?php
2
3
/**
4
 * Platine Framework
5
 *
6
 * Platine Framework is a lightweight, high-performance, simple and elegant
7
 * PHP Web framework
8
 *
9
 * This content is released under the MIT License (MIT)
10
 *
11
 * Copyright (c) 2020 Platine Framework
12
 *
13
 * Permission is hereby granted, free of charge, to any person obtaining a copy
14
 * of this software and associated documentation files (the "Software"), to deal
15
 * in the Software without restriction, including without limitation the rights
16
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
17
 * copies of the Software, and to permit persons to whom the Software is
18
 * furnished to do so, subject to the following conditions:
19
 *
20
 * The above copyright notice and this permission notice shall be included in all
21
 * copies or substantial portions of the Software.
22
 *
23
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
24
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
25
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
26
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
27
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
28
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
29
 * SOFTWARE.
30
 */
31
32
/**
33
 *  @file AuthorizationMiddleware.php
34
 *
35
 *  The Authorization middleware class
36
 *
37
 *  @package    Platine\Framework\Auth\Middleware
38
 *  @author Platine Developers team
39
 *  @copyright  Copyright (c) 2020
40
 *  @license    http://opensource.org/licenses/MIT  MIT License
41
 *  @link   http://www.iacademy.cf
42
 *  @version 1.0.0
43
 *  @filesource
44
 */
45
46
declare(strict_types=1);
47
48
namespace Platine\Framework\Auth\Middleware;
49
50
use Platine\Config\Config;
51
use Platine\Framework\Http\Response\RedirectResponse;
52
use Platine\Framework\Http\RouteHelper;
53
use Platine\Http\Handler\MiddlewareInterface;
54
use Platine\Http\Handler\RequestHandlerInterface;
55
use Platine\Http\ResponseInterface;
56
use Platine\Http\ServerRequestInterface;
57
use Platine\Route\Route;
58
use Platine\Session\Session;
59
60
/**
61
 * class AuthorizationMiddleware
62
 * @package Platine\Framework\Auth\Middleware
63
 */
64
class AuthorizationMiddleware implements MiddlewareInterface
65
{
66
67
    /**
68
     * The session instance to use
69
     * @var Session
70
     */
71
    protected Session $session;
72
73
    /**
74
     * The configuration instance
75
     * @var Config<T>
76
     */
77
    protected Config $config;
78
79
    /**
80
     * The route helper
81
     * @var RouteHelper
82
     */
83
    protected RouteHelper $routeHelper;
84
85
    /**
86
     * Create new instance
87
     * @param Session $session
88
     * @param Config $config
89
     * @param RouteHelper $routeHelper
90
     */
91
    public function __construct(
92
        Session $session,
93
        Config $config,
94
        RouteHelper $routeHelper
95
    ) {
96
        $this->session = $session;
97
        $this->config = $config;
98
        $this->routeHelper = $routeHelper;
99
    }
100
101
    /**
102
     * {@inheritdoc}
103
     */
104
    public function process(
105
        ServerRequestInterface $request,
106
        RequestHandlerInterface $handler
107
    ): ResponseInterface {
108
        //If no route has been match no need check for authorization
109
        /** @var Route $route|null */
110
        $route = $request->getAttribute(Route::class);
111
        if (!$route) {
112
            return $handler->handle($request);
113
        }
114
115
        $permission = $route->getAttribute('permission');
116
117
        if (empty($permission)) {
118
            return $handler->handle($request);
119
        }
120
121
        if (!$this->isAllowed($permission)) {
122
            $unauthorizedRoute = $this->config->get(
123
                'auth.authorization.unauthorized_route_name'
124
            );
125
126
            return new RedirectResponse(
127
                $this->routeHelper->generateUrl($unauthorizedRoute)
0 ignored issues
show
Bug introduced by
It seems like $unauthorizedRoute can also be of type null; however, parameter $name of Platine\Framework\Http\RouteHelper::generateUrl() does only seem to accept string, maybe add an additional type check? ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-type  annotation

127
                $this->routeHelper->generateUrl(/** @scrutinizer ignore-type */ $unauthorizedRoute)
Loading history...
128
            );
129
        }
130
131
        return $handler->handle($request);
132
    }
133
134
    /**
135
     * Whether the user is allowed or not
136
     * @param string $permission
137
     * @return bool
138
     */
139
    protected function isAllowed(string $permission): bool
140
    {
141
        $permissions = $this->session->get('permissions', []);
142
143
        return in_array($permission, $permissions);
144
    }
145
}
146