1
|
|
|
<?php |
2
|
|
|
namespace common\models; |
3
|
|
|
|
4
|
|
|
use Yii; |
5
|
|
|
use yii\base\NotSupportedException; |
6
|
|
|
use yii\behaviors\TimestampBehavior; |
7
|
|
|
use yii\db\ActiveRecord; |
8
|
|
|
use yii\web\IdentityInterface; |
9
|
|
|
|
10
|
|
|
/** |
11
|
|
|
* User model |
12
|
|
|
* |
13
|
|
|
* @property integer $id |
14
|
|
|
* @property string $username |
15
|
|
|
* @property string $password_hash |
16
|
|
|
* @property string $password_reset_token |
17
|
|
|
* @property string $email |
18
|
|
|
* @property string $auth_key |
19
|
|
|
* @property integer $status |
20
|
|
|
* @property integer $created_at |
21
|
|
|
* @property integer $updated_at |
22
|
|
|
* @property string $password write-only password |
23
|
|
|
*/ |
24
|
|
|
class User extends ActiveRecord implements IdentityInterface |
25
|
|
|
{ |
26
|
|
|
const STATUS_DELETED = 0; |
27
|
|
|
const STATUS_ACTIVE = 10; |
28
|
|
|
|
29
|
|
|
/** |
30
|
|
|
* @inheritdoc |
31
|
|
|
*/ |
32
|
|
|
public static function tableName() |
33
|
|
|
{ |
34
|
|
|
return '{{%user}}'; |
35
|
|
|
} |
36
|
|
|
|
37
|
|
|
/** |
38
|
|
|
* @inheritdoc |
39
|
|
|
*/ |
40
|
|
|
public function behaviors() |
41
|
|
|
{ |
42
|
|
|
return [ |
43
|
|
|
TimestampBehavior::className(), |
44
|
|
|
]; |
45
|
|
|
} |
46
|
|
|
|
47
|
|
|
/** |
48
|
|
|
* @inheritdoc |
49
|
|
|
*/ |
50
|
|
|
public function rules() |
51
|
|
|
{ |
52
|
|
|
return [ |
53
|
|
|
['status', 'default', 'value' => self::STATUS_ACTIVE], |
54
|
|
|
['status', 'in', 'range' => [self::STATUS_ACTIVE, self::STATUS_DELETED]], |
55
|
|
|
]; |
56
|
|
|
} |
57
|
|
|
|
58
|
|
|
/** |
59
|
|
|
* @inheritdoc |
60
|
|
|
*/ |
61
|
|
|
public static function findIdentity($id) |
62
|
|
|
{ |
63
|
|
|
return static::findOne(['id' => $id, 'status' => self::STATUS_ACTIVE]); |
|
|
|
|
64
|
|
|
} |
65
|
|
|
|
66
|
|
|
/** |
67
|
|
|
* @inheritdoc |
68
|
|
|
*/ |
69
|
|
|
public static function findIdentityByAccessToken($token, $type = null) |
70
|
|
|
{ |
71
|
|
|
throw new NotSupportedException('"findIdentityByAccessToken" is not implemented.'); |
72
|
|
|
} |
73
|
|
|
|
74
|
|
|
/** |
75
|
|
|
* Finds user by username |
76
|
|
|
* |
77
|
|
|
* @param string $username |
78
|
|
|
* @return static|null |
79
|
|
|
*/ |
80
|
|
|
public static function findByUsername($username) |
81
|
|
|
{ |
82
|
|
|
return static::findOne(['username' => $username, 'status' => self::STATUS_ACTIVE]); |
83
|
|
|
} |
84
|
|
|
|
85
|
|
|
/** |
86
|
|
|
* Finds user by password reset token |
87
|
|
|
* |
88
|
|
|
* @param string $token password reset token |
89
|
|
|
* @return static|null |
90
|
|
|
*/ |
91
|
|
|
public static function findByPasswordResetToken($token) |
92
|
|
|
{ |
93
|
|
|
if (!static::isPasswordResetTokenValid($token)) { |
94
|
|
|
return null; |
95
|
|
|
} |
96
|
|
|
|
97
|
|
|
return static::findOne([ |
98
|
|
|
'password_reset_token' => $token, |
99
|
|
|
'status' => self::STATUS_ACTIVE, |
100
|
|
|
]); |
101
|
|
|
} |
102
|
|
|
|
103
|
|
|
/** |
104
|
|
|
* Finds out if password reset token is valid |
105
|
|
|
* |
106
|
|
|
* @param string $token password reset token |
107
|
|
|
* @return boolean |
108
|
|
|
*/ |
109
|
|
|
public static function isPasswordResetTokenValid($token) |
110
|
|
|
{ |
111
|
|
|
if (empty($token)) { |
112
|
|
|
return false; |
113
|
|
|
} |
114
|
|
|
|
115
|
|
|
$timestamp = (int) substr($token, strrpos($token, '_') + 1); |
116
|
|
|
$expire = Yii::$app->params['user.passwordResetTokenExpire']; |
117
|
|
|
return $timestamp + $expire >= time(); |
118
|
|
|
} |
119
|
|
|
|
120
|
|
|
/** |
121
|
|
|
* @inheritdoc |
122
|
|
|
*/ |
123
|
|
|
public function getId() |
124
|
|
|
{ |
125
|
|
|
return $this->getPrimaryKey(); |
126
|
|
|
} |
127
|
|
|
|
128
|
|
|
/** |
129
|
|
|
* @inheritdoc |
130
|
|
|
*/ |
131
|
|
|
public function getAuthKey() |
132
|
|
|
{ |
133
|
|
|
return $this->auth_key; |
134
|
|
|
} |
135
|
|
|
|
136
|
|
|
/** |
137
|
|
|
* @inheritdoc |
138
|
|
|
*/ |
139
|
|
|
public function validateAuthKey($authKey) |
140
|
|
|
{ |
141
|
|
|
return $this->getAuthKey() === $authKey; |
142
|
|
|
} |
143
|
|
|
|
144
|
|
|
/** |
145
|
|
|
* Validates password |
146
|
|
|
* |
147
|
|
|
* @param string $password password to validate |
148
|
|
|
* @return boolean if password provided is valid for current user |
149
|
|
|
*/ |
150
|
|
|
public function validatePassword($password) |
151
|
|
|
{ |
152
|
|
|
return Yii::$app->security->validatePassword($password, $this->password_hash); |
153
|
|
|
} |
154
|
|
|
|
155
|
|
|
/** |
156
|
|
|
* Generates password hash from password and sets it to the model |
157
|
|
|
* |
158
|
|
|
* @param string $password |
159
|
|
|
*/ |
160
|
|
|
public function setPassword($password) |
161
|
|
|
{ |
162
|
|
|
$this->password_hash = Yii::$app->security->generatePasswordHash($password); |
163
|
|
|
} |
164
|
|
|
|
165
|
|
|
/** |
166
|
|
|
* Generates "remember me" authentication key |
167
|
|
|
*/ |
168
|
|
|
public function generateAuthKey() |
169
|
|
|
{ |
170
|
|
|
$this->auth_key = Yii::$app->security->generateRandomString(); |
171
|
|
|
} |
172
|
|
|
|
173
|
|
|
/** |
174
|
|
|
* Generates new password reset token |
175
|
|
|
*/ |
176
|
|
|
public function generatePasswordResetToken() |
177
|
|
|
{ |
178
|
|
|
$this->password_reset_token = Yii::$app->security->generateRandomString() . '_' . time(); |
179
|
|
|
} |
180
|
|
|
|
181
|
|
|
/** |
182
|
|
|
* Removes password reset token |
183
|
|
|
*/ |
184
|
|
|
public function removePasswordResetToken() |
185
|
|
|
{ |
186
|
|
|
$this->password_reset_token = null; |
187
|
|
|
} |
188
|
|
|
} |
189
|
|
|
|
If you return a value from a function or method, it should be a sub-type of the type that is given by the parent type f.e. an interface, or abstract method. This is more formally defined by the Lizkov substitution principle, and guarantees that classes that depend on the parent type can use any instance of a child type interchangably. This principle also belongs to the SOLID principles for object oriented design.
Let’s take a look at an example:
Our function
my_function
expects aPost
object, and outputs the author of the post. The base classPost
returns a simple string and outputting a simple string will work just fine. However, the child classBlogPost
which is a sub-type ofPost
instead decided to return anobject
, and is therefore violating the SOLID principles. If aBlogPost
were passed tomy_function
, PHP would not complain, but ultimately fail when executing thestrtoupper
call in its body.