ReauthenticationController   A
last analyzed

Complexity

Total Complexity 5

Size/Duplication

Total Lines 67
Duplicated Lines 0 %

Coupling/Cohesion

Components 1
Dependencies 4

Importance

Changes 0
Metric Value
wmc 5
lcom 1
cbo 4
dl 0
loc 67
rs 10
c 0
b 0
f 0

3 Methods

Rating   Name   Duplication   Size   Complexity  
A processPassword() 0 20 2
A processTwofactor() 0 21 2
A setSession() 0 6 1
1
<?php
2
3
declare(strict_types=1);
4
5
namespace Cortex\Auth\Http\Controllers\Frontarea;
6
7
use Illuminate\Http\Request;
8
use Illuminate\Support\Facades\Hash;
9
use Cortex\Auth\Traits\TwoFactorAuthenticatesUsers;
10
use Cortex\Foundation\Http\Controllers\AuthenticatedController;
11
12
class ReauthenticationController extends AuthenticatedController
13
{
14
    use TwoFactorAuthenticatesUsers;
15
16
    /**
17
     * @param Request $request
18
     *
19
     * @return \Illuminate\Http\JsonResponse|\Illuminate\Http\RedirectResponse
20
     */
21
    public function processPassword(Request $request)
22
    {
23
        $redirect_url = session('cortex.auth.reauthentication.intended');
24
        $session_name = session('cortex.auth.reauthentication.session_name');
25
26
        if (Hash::check($request->input('password'), request()->user($this->getGuard())->password)) {
0 ignored issues
show
Bug introduced by
It seems like $request->input('password') targeting Illuminate\Http\Concerns...ractsWithInput::input() can also be of type array or null; however, Illuminate\Support\Facades\Hash::check() does only seem to accept string, maybe add an additional type check?

This check looks at variables that are passed out again to other methods.

If the outgoing method call has stricter type requirements than the method itself, an issue is raised.

An additional type check may prevent trouble.

Loading history...
27
            $this->setSession($session_name);
28
29
            return intend([
30
                'intended' => url($redirect_url),
31
            ]);
32
        }
33
34
        return intend([
35
            'intended' => url($redirect_url),
36
            'withErrors' => [
37
                'password' => trans('cortex/auth::messages.auth.failed'),
38
            ],
39
        ]);
40
    }
41
42
    /**
43
     * @param Request $request
44
     *
45
     * @return \Illuminate\Http\JsonResponse|\Illuminate\Http\RedirectResponse
46
     */
47
    public function processTwofactor(Request $request)
48
    {
49
        $redirect_url = session('cortex.auth.reauthentication.intended');
50
        $session_name = session('cortex.auth.reauthentication.session_name');
51
52
        $user = $request->user($this->getGuard());
53
        $token = (int) $request->input('token');
54
55
        if ($this->attemptTwoFactor($user, $token)) {
56
            $this->setSession($session_name);
57
58
            return intend([
59
                'intended' => url($redirect_url),
60
            ]);
61
        }
62
63
        return intend([
64
            'intended' => url($redirect_url),
65
            'withErrors' => ['token' => trans('cortex/auth::messages.verification.twofactor.invalid_token')],
66
        ]);
67
    }
68
69
    /**
70
     * @param $session_name
71
     */
72
    protected function setSession($session_name)
73
    {
74
        session()->put($session_name, time());
75
        session()->forget('cortex.auth.reauthentication.intended');
76
        session()->forget('cortex.auth.reauthentication.session_name');
77
    }
78
}
79