Passed
Push — develop ( d3c53a...e28085 )
by nguereza
14:20
created

CsrfTokenMiddleware::__construct()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 2
Code Lines 0

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 1
eloc 0
c 1
b 0
f 0
nc 1
nop 1
dl 0
loc 2
rs 10
1
<?php
2
3
/**
4
 * Platine Framework
5
 *
6
 * Platine Framework is a lightweight, high-performance, simple and elegant PHP
7
 * Web framework
8
 *
9
 * This content is released under the MIT License (MIT)
10
 *
11
 * Copyright (c) 2020 Platine Framework
12
 *
13
 * Permission is hereby granted, free of charge, to any person obtaining a copy
14
 * of this software and associated documentation files (the "Software"), to deal
15
 * in the Software without restriction, including without limitation the rights
16
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
17
 * copies of the Software, and to permit persons to whom the Software is
18
 * furnished to do so, subject to the following conditions:
19
 *
20
 * The above copyright notice and this permission notice shall be included in all
21
 * copies or substantial portions of the Software.
22
 *
23
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
24
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
25
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
26
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
27
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
28
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
29
 * SOFTWARE.
30
 */
31
32
declare(strict_types=1);
33
34
namespace Platine\Framework\Http\Middleware;
35
36
use Platine\Framework\Security\Csrf\CsrfManager;
37
use Platine\Http\Handler\MiddlewareInterface;
38
use Platine\Http\Handler\RequestHandlerInterface;
39
use Platine\Http\ResponseInterface;
40
use Platine\Http\ServerRequestInterface;
41
use Platine\Route\Route;
42
43
/**
44
* @class CsrfTokenMiddleware
45
* @package Platine\Framework\Http\Middleware
46
*/
47
class CsrfTokenMiddleware implements MiddlewareInterface
48
{
49
    /**
50
     * Create new instance
51
     * @param CsrfManager $csrfManager
52
     */
53
    public function __construct(protected CsrfManager $csrfManager)
54
    {
55
    }
56
57
58
    /**
59
    * {@inheritdoc}
60
    */
61
    public function process(
62
        ServerRequestInterface $request,
63
        RequestHandlerInterface $handler
64
    ): ResponseInterface {
65
        if ($this->shouldBeProcessed($request) === false) {
66
            return $handler->handle($request);
67
        }
68
69
        $newRequest = $request->withAttribute('csrf_token', $this->csrfManager->getToken());
70
71
        return $handler->handle($newRequest);
72
    }
73
74
   /**
75
     * Whether we can process this request
76
     * @param ServerRequestInterface $request
77
     * @return bool
78
     */
79
    protected function shouldBeProcessed(ServerRequestInterface $request): bool
80
    {
81
       //If no route has been match no need check for CSRF
82
        /** @var Route|null $route */
83
        $route = $request->getAttribute(Route::class);
84
        if ($route === null) {
85
            return false;
86
        }
87
88
        return true;
89
    }
90
}
91