1
|
|
|
<?php |
2
|
|
|
|
3
|
|
|
namespace rhertogh\Yii2SecurityTxt\controllers\web\wellknown; |
4
|
|
|
|
5
|
|
|
use Exception; |
6
|
|
|
use rhertogh\Yii2SecurityTxt\controllers\web\SecurityTxtWellKnownController; |
7
|
|
|
use rhertogh\Yii2SecurityTxt\helpers\GPG\GPGHelper; |
8
|
|
|
use Yii; |
9
|
|
|
use yii\base\Action; |
10
|
|
|
use yii\base\InvalidConfigException; |
11
|
|
|
use yii\web\Response; |
12
|
|
|
|
13
|
|
|
/** |
14
|
|
|
* @property SecurityTxtWellKnownController $controller |
15
|
|
|
* @since 1.0.0 |
16
|
|
|
*/ |
17
|
|
|
class SecurityTxtAction extends Action |
18
|
|
|
{ |
19
|
|
|
/** |
20
|
|
|
* |
21
|
|
|
* @throws InvalidConfigException |
22
|
|
|
* @throws Exception |
23
|
|
|
* @since 1.0.0 |
24
|
|
|
*/ |
25
|
3 |
|
public function run() |
26
|
|
|
{ |
27
|
3 |
|
Yii::beginProfile('Generate security.txt', __METHOD__); |
28
|
|
|
|
29
|
3 |
|
$module = $this->controller->module; |
30
|
|
|
|
31
|
3 |
|
$expires = $module->getParsedExpires(); |
32
|
|
|
|
33
|
3 |
|
$fields = [ |
34
|
3 |
|
'policy' => $module->getParsedPolicy(), |
35
|
3 |
|
'contact' => $module->getParsedContact(), |
36
|
3 |
|
'preferredLanguages' => $module->getParsedPreferredLanguages(), |
37
|
3 |
|
'encryption' => $module->getParsedEncryption(), |
38
|
3 |
|
'acknowledgments' => $module->getParsedAcknowledgments(), |
39
|
3 |
|
'hiring' => $module->getParsedHiring(), |
40
|
3 |
|
'canonical' => $module->getParsedCanonical(), |
41
|
3 |
|
'expires' => $expires, |
42
|
3 |
|
]; |
43
|
|
|
|
44
|
3 |
|
$output = ''; |
45
|
3 |
|
if ($module->headerComment) { |
46
|
2 |
|
$output .= $this->generateCommentBlock($module->headerComment) . PHP_EOL; |
47
|
|
|
} |
48
|
|
|
|
49
|
3 |
|
foreach ($fields as $fieldName => $fieldValue) { |
50
|
3 |
|
$fieldOutput = $this->generateFieldBlock(ucfirst($fieldName), $fieldValue); |
51
|
3 |
|
if ($fieldOutput) { |
52
|
3 |
|
if (!empty($module->fieldComments[$fieldName])) { |
53
|
2 |
|
$output .= $this->generateCommentBlock($module->fieldComments[$fieldName]); |
54
|
|
|
} |
55
|
3 |
|
$output .= $fieldOutput . PHP_EOL; |
56
|
|
|
} |
57
|
|
|
} |
58
|
|
|
|
59
|
3 |
|
if ($module->footerComment) { |
60
|
2 |
|
$output .= $this->generateCommentBlock($module->footerComment) . PHP_EOL; |
61
|
|
|
} |
62
|
|
|
|
63
|
3 |
|
$output = substr($output, 0, - strlen(PHP_EOL)); |
64
|
|
|
|
65
|
3 |
|
if ($module->pgpPrivateKey) { |
66
|
2 |
|
$output = GPGHelper::sign($output, $module->pgpPrivateKey); |
67
|
|
|
} |
68
|
|
|
|
69
|
3 |
|
Yii::$app->response->format = Response::FORMAT_RAW; |
70
|
3 |
|
Yii::$app->response->headers->set('Content-Type', 'text/plain; charset=utf-8'); |
71
|
|
|
|
72
|
3 |
|
if ($module->cacheControl) { |
73
|
3 |
|
if (is_int($module->cacheControl)) { |
74
|
1 |
|
$maxAge = $module->cacheControl; |
75
|
|
|
} else { |
76
|
2 |
|
$maxAge = $expires->getTimestamp() - time(); |
77
|
|
|
} |
78
|
3 |
|
Yii::$app->response->headers->set('Cache-Control', 'public, max-age=' . $maxAge); |
79
|
|
|
} |
80
|
|
|
|
81
|
3 |
|
Yii::endProfile('Generate security.txt', __METHOD__); |
82
|
3 |
|
return $output; |
83
|
|
|
} |
84
|
|
|
|
85
|
|
|
/** |
86
|
|
|
* @since 1.0.0 |
87
|
|
|
*/ |
88
|
3 |
|
protected function generateFieldBlock(string $fieldName, array|string|\DateTimeImmutable $fieldValue): string |
89
|
|
|
{ |
90
|
3 |
|
if (is_array($fieldValue)) { |
|
|
|
|
91
|
3 |
|
return implode(array_map(fn($val) => $this->generateFieldBlock($fieldName, $val),$fieldValue)); |
92
|
|
|
} |
93
|
|
|
|
94
|
3 |
|
if ($fieldValue instanceof \DateTimeImmutable){ |
95
|
3 |
|
$fieldValue = $fieldValue->setTimezone(new \DateTimeZone('UTC'))->format(\DateTime::RFC3339); |
96
|
|
|
} |
97
|
|
|
|
98
|
3 |
|
if (is_string($fieldValue)) { |
99
|
3 |
|
if ($fieldValue) { |
100
|
3 |
|
return $fieldName . ': ' . $fieldValue . PHP_EOL; |
101
|
|
|
} else { |
102
|
1 |
|
return ''; |
103
|
|
|
} |
104
|
|
|
} |
105
|
|
|
|
106
|
|
|
throw new InvalidConfigException('Unknown type for "' . $fieldName . '": ' . get_debug_type($fieldValue)); |
107
|
|
|
} |
108
|
|
|
|
109
|
|
|
/** |
110
|
|
|
* @since 1.0.0 |
111
|
|
|
*/ |
112
|
2 |
|
protected function generateCommentBlock(string $comment): string |
113
|
|
|
{ |
114
|
2 |
|
return '# ' . str_replace("\n", "\n# ", $comment) . PHP_EOL; |
115
|
|
|
} |
116
|
|
|
} |
117
|
|
|
|