1 | <?php |
||
40 | final class SessionMiddleware implements MiddlewareInterface |
||
41 | { |
||
42 | const ISSUED_AT_CLAIM = 'iat'; |
||
43 | const SESSION_CLAIM = 'session-data'; |
||
44 | const SESSION_ATTRIBUTE = 'session'; |
||
45 | const DEFAULT_COOKIE = 'slsession'; |
||
46 | const DEFAULT_REFRESH_TIME = 60; |
||
47 | |||
48 | /** |
||
49 | * @var Signer |
||
50 | */ |
||
51 | private $signer; |
||
52 | |||
53 | /** |
||
54 | * @var string |
||
55 | */ |
||
56 | private $signatureKey; |
||
57 | |||
58 | /** |
||
59 | * @var string |
||
60 | */ |
||
61 | private $verificationKey; |
||
62 | |||
63 | /** |
||
64 | * @var int |
||
65 | */ |
||
66 | private $expirationTime; |
||
67 | |||
68 | /** |
||
69 | * @var int |
||
70 | */ |
||
71 | private $refreshTime; |
||
72 | |||
73 | /** |
||
74 | * @var Parser |
||
75 | */ |
||
76 | private $tokenParser; |
||
77 | |||
78 | /** |
||
79 | * @var SetCookie |
||
80 | */ |
||
81 | private $defaultCookie; |
||
82 | |||
83 | /** |
||
84 | * @var CurrentTimeProviderInterface |
||
85 | */ |
||
86 | private $currentTimeProvider; |
||
87 | |||
88 | /** |
||
89 | * @param Signer $signer |
||
90 | * @param string $signatureKey |
||
91 | * @param string $verificationKey |
||
92 | * @param SetCookie $defaultCookie |
||
93 | * @param Parser $tokenParser |
||
94 | * @param int $expirationTime |
||
95 | * @param CurrentTimeProviderInterface $currentTimeProvider |
||
96 | * @param int $refreshTime |
||
97 | */ |
||
98 | 10 | public function __construct( |
|
117 | |||
118 | /** |
||
119 | * This constructor simplifies instantiation when using HTTPS (REQUIRED!) and symmetric key encription |
||
120 | * |
||
121 | * @param string $symmetricKey |
||
122 | * @param int $expirationTime |
||
123 | * |
||
124 | * @return self |
||
125 | */ |
||
126 | 2 | public static function fromSymmetricKeyDefaults(string $symmetricKey, int $expirationTime) : SessionMiddleware |
|
141 | |||
142 | /** |
||
143 | * This constructor simplifies instantiation when using HTTPS (REQUIRED!) and asymmetric key encription |
||
144 | * based on RSA keys |
||
145 | * |
||
146 | * @param string $privateRsaKey |
||
147 | * @param string $publicRsaKey |
||
148 | * @param int $expirationTime |
||
149 | * |
||
150 | * @return self |
||
151 | */ |
||
152 | 2 | public static function fromAsymmetricKeyDefaults( |
|
170 | |||
171 | /** |
||
172 | * {@inheritdoc} |
||
173 | * |
||
174 | * @throws \InvalidArgumentException |
||
175 | * @throws \OutOfBoundsException |
||
176 | */ |
||
177 | 43 | public function process(Request $request, DelegateInterface $delegate) : Response |
|
188 | |||
189 | /** |
||
190 | * Extract the token from the given request object |
||
191 | * |
||
192 | * @param Request $request |
||
193 | * |
||
194 | * @return Token|null |
||
195 | */ |
||
196 | 43 | private function parseToken(Request $request) |
|
217 | |||
218 | /** |
||
219 | * @param Token|null $token |
||
220 | * |
||
221 | * @return SessionInterface |
||
222 | */ |
||
223 | 43 | public function extractSessionContainer(Token $token = null) : SessionInterface |
|
237 | |||
238 | /** |
||
239 | * @param SessionInterface $sessionContainer |
||
240 | * @param Response $response |
||
241 | * @param Token $token |
||
242 | * |
||
243 | * @return Response |
||
244 | * |
||
245 | * @throws \InvalidArgumentException |
||
246 | */ |
||
247 | 43 | private function appendToken(SessionInterface $sessionContainer, Response $response, Token $token = null) : Response |
|
262 | |||
263 | /** |
||
264 | * {@inheritDoc} |
||
265 | */ |
||
266 | 9 | private function shouldTokenBeRefreshed(Token $token) : bool |
|
274 | |||
275 | /** |
||
276 | * @param SessionInterface $sessionContainer |
||
277 | * |
||
278 | * @return SetCookie |
||
279 | */ |
||
280 | 20 | private function getTokenCookie(SessionInterface $sessionContainer) : SetCookie |
|
296 | |||
297 | /** |
||
298 | * @return SetCookie |
||
299 | */ |
||
300 | 3 | private function getExpirationCookie() : SetCookie |
|
311 | |||
312 | 21 | private function timestamp() : int |
|
318 | } |
||
319 |