Completed
Push — master ( 658fea...3b2f24 )
by Fabio
07:26
created

TWsatLayout::onLoad()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 5
Code Lines 3

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 1
eloc 3
nc 1
nop 1
dl 0
loc 5
rs 9.4285
c 0
b 0
f 0
1
<?php
2
3
namespace Prado\Wsat\pages\layout;
4
5
use Prado\Web\UI\TTemplateControl;
6
use Prado\Wsat\pages\TWsatLogin;
7
8
/**
9
 * Description of MainLayout
10
 *
11
 * @author daniels
12
 */
13
class TWsatLayout extends TTemplateControl
14
{
15
16
        public function onLoad($param)
17
        {
18
                parent::onLoad($param);
19
                $this->validateSecurity();
20
        }
21
22
        private function validateSecurity()
23
        {
24
                if ($this->Session["wsat_password"] !== $this->getService()->getPassword())
0 ignored issues
show
Bug introduced by
It seems like you code against a concrete implementation and not the interface Prado\IService as the method getPassword() does only exist in the following implementations of said interface: Prado\Wsat\TWsatService.

Let’s take a look at an example:

interface User
{
    /** @return string */
    public function getPassword();
}

class MyUser implements User
{
    public function getPassword()
    {
        // return something
    }

    public function getDisplayName()
    {
        // return some name.
    }
}

class AuthSystem
{
    public function authenticate(User $user)
    {
        $this->logger->info(sprintf('Authenticating %s.', $user->getDisplayName()));
        // do something.
    }
}

In the above example, the authenticate() method works fine as long as you just pass instances of MyUser. However, if you now also want to pass a different implementation of User which does not have a getDisplayName() method, the code will break.

Available Fixes

  1. Change the type-hint for the parameter:

    class AuthSystem
    {
        public function authenticate(MyUser $user) { /* ... */ }
    }
    
  2. Add an additional type-check:

    class AuthSystem
    {
        public function authenticate(User $user)
        {
            if ($user instanceof MyUser) {
                $this->logger->info(/** ... */);
            }
    
            // or alternatively
            if ( ! $user instanceof MyUser) {
                throw new \LogicException(
                    '$user must be an instance of MyUser, '
                   .'other instances are not supported.'
                );
            }
    
        }
    }
    
Note: PHP Analyzer uses reverse abstract interpretation to narrow down the types inside the if block in such a case.
  1. Add the method to the interface:

    interface User
    {
        /** @return string */
        public function getPassword();
    
        /** @return string */
        public function getDisplayName();
    }
    
Loading history...
25
                {
26
                        if (!$this->getPage() instanceof TWsatLogin)
27
                        {
28
                                $url = $this->Service->constructUrl('TWsatLogin');
29
                                $this->Response->redirect($url);
30
                        }
31
                }
32
        }
33
34
        public function logout()
35
        {
36
                $this->Session["wsat_password"] = "";
37
                $url = $this->Service->constructUrl('TWsatLogin');
38
                $this->Response->redirect($url);
39
        }
40
41
}