Test Failed
Push — develop ( 149858...5cd5e7 )
by nguereza
03:42
created

CorsMiddleware::process()   A

Complexity

Conditions 2
Paths 2

Size

Total Lines 17
Code Lines 7

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 2
eloc 7
c 1
b 0
f 0
nc 2
nop 2
dl 0
loc 17
rs 10
1
<?php
2
3
/**
4
 * Platine Framework
5
 *
6
 * Platine Framework is a lightweight, high-performance, simple and elegant PHP
7
 * Web framework
8
 *
9
 * This content is released under the MIT License (MIT)
10
 *
11
 * Copyright (c) 2020 Platine Framework
12
 *
13
 * Permission is hereby granted, free of charge, to any person obtaining a copy
14
 * of this software and associated documentation files (the "Software"), to deal
15
 * in the Software without restriction, including without limitation the rights
16
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
17
 * copies of the Software, and to permit persons to whom the Software is
18
 * furnished to do so, subject to the following conditions:
19
 *
20
 * The above copyright notice and this permission notice shall be included in all
21
 * copies or substantial portions of the Software.
22
 *
23
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
24
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
25
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
26
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
27
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
28
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
29
 * SOFTWARE.
30
 */
31
32
/**
33
 *  @file CorsMiddleware.php
34
 *
35
 *  The CORS middleware class is used to check the CORS policies
36
 *
37
 *  @package    Platine\Framework\Http\Middleware
38
 *  @author Platine Developers Team
39
 *  @copyright  Copyright (c) 2020
40
 *  @license    http://opensource.org/licenses/MIT  MIT License
41
 *  @link   http://www.iacademy.cf
42
 *  @version 1.0.0
43
 *  @filesource
44
 */
45
46
declare(strict_types=1);
47
48
namespace Platine\Framework\Http\Middleware;
49
50
use Platine\Config\Config;
51
use Platine\Http\Handler\MiddlewareInterface;
52
use Platine\Http\Handler\RequestHandlerInterface;
53
use Platine\Http\Response;
54
use Platine\Http\ResponseInterface;
55
use Platine\Http\ServerRequestInterface;
56
use Platine\Logger\LoggerInterface;
57
use Platine\Stdlib\Helper\Str;
58
59
/**
60
 * @class CorsMiddleware
61
 * @package Platine\Framework\Http\Middleware
62
 * @template T
63
 */
64
class CorsMiddleware implements MiddlewareInterface
65
{
66
67
    /**
68
     * The configuration instance
69
     * @var Config<T>
70
     */
71
    protected Config $config;
72
73
    /**
74
     * The logger instance
75
     * @var LoggerInterface
76
     */
77
    protected LoggerInterface $logger;
78
79
    /**
80
     * Create new instance
81
     * @param LoggerInterface $logger
82
     * @param Config $config
83
     */
84
    public function __construct(
85
        LoggerInterface $logger,
86
        Config $config
87
    ) {
88
        $this->config = $config;
89
        $this->logger = $logger;
90
    }
91
92
    /**
93
     * {@inheritdoc}
94
     */
95
    public function process(
96
        ServerRequestInterface $request,
97
        RequestHandlerInterface $handler
98
    ): ResponseInterface {
99
        if ($request->getMethod() !== 'OPTIONS') {
100
            return $handler->handle($request);
101
        }
102
103
        $this->logger->info(
104
            'CORS Request for {method}:{url}',
105
            [
106
                'method' => $request->getMethod(),
107
                'url' => (string) $request->getUri(),
108
            ]
109
        );
110
111
        return $this->corsResponse();
112
    }
113
114
    /**
115
     * Return the CORS response
116
     * @return ResponseInterface
117
     */
118
    protected function corsResponse(): ResponseInterface
119
    {
120
        $origin = $this->config->get('security.cors.origin', '*');
121
        $headers = $this->config->get('security.cors.headers', [
122
            'Origin',
123
            'X-Requested-With',
124
            'Content-Type',
125
            'Accept',
126
            'Connection',
127
            'User-Agent',
128
            'Cookie',
129
            'Cache-Control',
130
            'token',
131
        ]);
132
        $methods = $this->config->get(
133
            'security.cors.methods',
134
            ['GET', 'OPTIONS', 'HEAD', 'PUT', 'POST', 'DELETE']
135
        );
136
        $credentials = $this->config->get('security.cors.credentials', true);
137
        $maxAge = $this->config->get('security.cors.max_age', 1800);
138
139
        $response = (new Response(204))
140
                            ->withHeader('Access-Control-Allow-Credentials', Str::stringify($credentials))
141
                            ->withHeader('Access-Control-Max-Age', Str::stringify($maxAge))
142
                            ->withHeader('Access-Control-Allow-Origin', $origin)
143
                            ->withHeader('Access-Control-Allow-Methods', implode(', ', $methods))
144
                            ->withHeader('Access-Control-Allow-Headers', implode(', ', $headers));
145
146
        return $response;
147
    }
148
}
149