ResourceServerMiddleware::process()   A
last analyzed

Complexity

Conditions 2
Paths 2

Size

Total Lines 20
Code Lines 9

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 2
eloc 9
c 1
b 0
f 0
nc 2
nop 2
dl 0
loc 20
rs 9.9666
1
<?php
2
3
/**
4
 * Platine OAuth2
5
 *
6
 * Platine OAuth2 is a library that implements the OAuth2 specification
7
 *
8
 * This content is released under the MIT License (MIT)
9
 *
10
 * Copyright (c) 2020 Platine OAuth2
11
 *
12
 * Permission is hereby granted, free of charge, to any person obtaining a copy
13
 * of this software and associated documentation files (the "Software"), to deal
14
 * in the Software without restriction, including without limitation the rights
15
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
16
 * copies of the Software, and to permit persons to whom the Software is
17
 * furnished to do so, subject to the following conditions:
18
 *
19
 * The above copyright notice and this permission notice shall be included in all
20
 * copies or substantial portions of the Software.
21
 *
22
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
23
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
24
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
25
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
26
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
27
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
28
 * SOFTWARE.
29
 */
30
31
declare(strict_types=1);
32
33
namespace Platine\OAuth2\Middleware;
34
35
use Platine\Http\Handler\MiddlewareInterface;
36
use Platine\Http\Handler\RequestHandlerInterface;
37
use Platine\Http\ResponseInterface;
38
use Platine\Http\ServerRequestInterface;
39
use Platine\OAuth2\Entity\AccessToken;
40
use Platine\OAuth2\Exception\InvalidAccessTokenException;
41
use Platine\OAuth2\ResourceServerInterface;
42
use Platine\OAuth2\Response\OAuthJsonResponse;
43
44
/**
45
 * Middleware for a resource server
46
 *
47
 * This middleware aims to sit very early in your pipeline. It will check if a request has an access token,
48
 * and if so, will try to validate it. If the token is invalid, the middleware will immediately return.
49
 *
50
 * If the token is valid, it will store it as part of the request under the attribute "oauth_token",
51
 * so that it can be used later one by a permission system, for instance
52
 *
53
 * @class ResourceServerMiddleware
54
 * @package Platine\OAuth2\Middleware
55
 */
56
class ResourceServerMiddleware implements MiddlewareInterface
57
{
58
    /**
59
     * Create new instance
60
     * @param ResourceServerInterface $resourceServer
61
     */
62
    public function __construct(
63
        protected ResourceServerInterface $resourceServer
64
    ) {
65
    }
66
67
68
    /**
69
     * {@inheritdoc}
70
     */
71
    public function process(
72
        ServerRequestInterface $request,
73
        RequestHandlerInterface $handler
74
    ): ResponseInterface {
75
        $scopes = $request->getAttribute('scopes', []);
76
        try {
77
            $token = $this->resourceServer->getAccessToken($request, $scopes);
78
        } catch (InvalidAccessTokenException $ex) {
79
            // If we're here, this means that there was an access token, but it's either expired
80
            // or invalid. If that's the case we must immediately return
81
            return new OAuthJsonResponse(
82
                [
83
                    'error' => $ex->getCode(),
84
                    'error_description' => $ex->getMessage(),
85
                ],
86
                401
87
            );
88
        }
89
90
        return $handler->handle($request->withAttribute(AccessToken::class, $token));
91
    }
92
}
93