Complex classes like LDAPMemberExtension often do a lot of different things. To break such a class down, we need to identify a cohesive component within that class. A common approach to find such a component is to look for fields/methods that share the same prefixes, or suffixes. You can also have a look at the cohesion graph to spot any un-connected, or weakly-connected components.
Once you have determined the fields that belong together, you can apply the Extract Class refactoring. If the component makes sense as a sub-class, Extract Subclass is also a candidate, and is often faster.
While breaking up the class, it is a good idea to analyze how other classes use LDAPMemberExtension, and based on these observations, apply Extract Interface, too.
| 1 | <?php  | 
            ||
| 7 | class LDAPMemberExtension extends DataExtension  | 
            ||
| 
                                                                                                    
                        
                         | 
                |||
| 8 | { | 
            ||
| 9 | /**  | 
            ||
| 10 | * @var array  | 
            ||
| 11 | */  | 
            ||
| 12 | private static $db = array(  | 
            ||
| 13 | // Unique user identifier, same field is used by SAMLMemberExtension  | 
            ||
| 14 | 'GUID' => 'Varchar(50)',  | 
            ||
| 15 | 'Username' => 'Varchar(64)',  | 
            ||
| 16 | 'IsImportedFromLDAP' => 'Boolean',  | 
            ||
| 17 | 'IsExpired' => 'Boolean',  | 
            ||
| 18 | 'LastSynced' => 'SS_Datetime',  | 
            ||
| 19 | );  | 
            ||
| 20 | |||
| 21 | /**  | 
            ||
| 22 |      * These fields are used by {@link LDAPMemberSync} to map specific AD attributes | 
            ||
| 23 |      * to {@link Member} fields. | 
            ||
| 24 | *  | 
            ||
| 25 | * @var array  | 
            ||
| 26 | * @config  | 
            ||
| 27 | */  | 
            ||
| 28 | private static $ldap_field_mappings = array(  | 
            ||
| 29 | 'samaccountname' => 'Username',  | 
            ||
| 30 | 'givenname' => 'FirstName',  | 
            ||
| 31 | 'sn' => 'Surname',  | 
            ||
| 32 | 'mail' => 'Email',  | 
            ||
| 33 | );  | 
            ||
| 34 | |||
| 35 | /**  | 
            ||
| 36 | * The location (relative to /assets) where to save thumbnailphoto data.  | 
            ||
| 37 | *  | 
            ||
| 38 | * @var string  | 
            ||
| 39 | * @config  | 
            ||
| 40 | */  | 
            ||
| 41 | private static $ldap_thumbnail_path = 'Uploads';  | 
            ||
| 42 | |||
| 43 | /**  | 
            ||
| 44 | * When enabled, LDAP managed users have their data written back to LDAP  | 
            ||
| 45 |      * This is a push to LDAP, rather than {@link LDAPMemberSyncTask} | 
            ||
| 46 | * which pulls from LDAP instead.  | 
            ||
| 47 | *  | 
            ||
| 48 | * This requires setting write permissions on the user who talks to LDAP,  | 
            ||
| 49 | * which is why it's disabled by default.  | 
            ||
| 50 | *  | 
            ||
| 51 | * Note that some constants must be configured in your environment file  | 
            ||
| 52 | * for this to work:  | 
            ||
| 53 | *  | 
            ||
| 54 | * LDAP_DOMAIN - the base DN of the directory. e.g. "DN=mydomain,DC=com"  | 
            ||
| 55 | * LDAP_NEW_USERS_OBJECT_CATEGORY - the type of object. e.g. "CN=Person,CN=Schema,DC=mydomain,DC=com"  | 
            ||
| 56 | * LDAP_NEW_USERS_DN - where to place users in the directory. e.g. "OU=Users,DC=mydomain,DC=com"  | 
            ||
| 57 | *  | 
            ||
| 58 | * @var bool  | 
            ||
| 59 | * @config  | 
            ||
| 60 | */  | 
            ||
| 61 | private static $reverse_sync_ldap = false;  | 
            ||
| 62 | |||
| 63 | /**  | 
            ||
| 64 | * If enabled, new users written are also created in LDAP.  | 
            ||
| 65 | *  | 
            ||
| 66 | * This requires setting write permissions on the user who talks to LDAP,  | 
            ||
| 67 | * which is why it's disabled by default.  | 
            ||
| 68 | *  | 
            ||
| 69 |      * Please see {@link $reverse_sync_ldap} for constants that must be configured in | 
            ||
| 70 | * your environment file for this to work.  | 
            ||
| 71 | *  | 
            ||
| 72 | * @var bool  | 
            ||
| 73 | * @config  | 
            ||
| 74 | */  | 
            ||
| 75 | private static $create_new_users_in_ldap = false;  | 
            ||
| 76 | |||
| 77 | /**  | 
            ||
| 78 | * @var array  | 
            ||
| 79 | */  | 
            ||
| 80 | private static $dependencies = array(  | 
            ||
| 81 | 'ldapService' => '%$LDAPService',  | 
            ||
| 82 | );  | 
            ||
| 83 | |||
| 84 | public function updateSummaryFields(&$fields)  | 
            ||
| 88 | |||
| 89 | /**  | 
            ||
| 90 | * @param FieldList $fields  | 
            ||
| 91 | */  | 
            ||
| 92 | public function updateCMSFields(FieldList $fields)  | 
            ||
| 139 | |||
| 140 | /**  | 
            ||
| 141 | * Creates a new LDAP user given the current Member details. Assumption is  | 
            ||
| 142 | * the record has been validated for the presence of FirstName, Surname, Email,  | 
            ||
| 143 | * and Username prior to the request being sent to LDAP.  | 
            ||
| 144 | */  | 
            ||
| 145 | public function createUser()  | 
            ||
| 187 | |||
| 188 | /**  | 
            ||
| 189 | * Sync the Member data back to the corresponding LDAP user object.  | 
            ||
| 190 | *  | 
            ||
| 191 | * This is effectively a reverse sync, so we don't want to be doing  | 
            ||
| 192 | * this onBeforeWrite as LDAPMemberSyncTask could get it into a loop.  | 
            ||
| 193 | * This method should be called explicitly when a sync of the  | 
            ||
| 194 | * Platform Dashboard user back to LDAP is required.  | 
            ||
| 195 | *  | 
            ||
| 196 | * @throws ValidationException  | 
            ||
| 197 | */  | 
            ||
| 198 | public function sync()  | 
            ||
| 237 | |||
| 238 | public function validate(ValidationResult $validationResult)  | 
            ||
| 259 | |||
| 260 | /**  | 
            ||
| 261 | * Ensure the user belongs to the correct groups in LDAP, making the  | 
            ||
| 262 | * assumption that the assigned groups are correct.  | 
            ||
| 263 | * This is considered a reverse sync back to LDAP.  | 
            ||
| 264 | *  | 
            ||
| 265 | * This also removes them from LDAP groups if they've been taken out of one.  | 
            ||
| 266 | * It will not affect group membership of non-mapped groups, so it will  | 
            ||
| 267 | * not touch such internal AD groups like "Domain Users".  | 
            ||
| 268 | */  | 
            ||
| 269 | public function syncGroups()  | 
            ||
| 357 | |||
| 358 | /**  | 
            ||
| 359 | * Given a group DN, look up the group membership data in LDAP.  | 
            ||
| 360 | *  | 
            ||
| 361 | * @param string $groupDn  | 
            ||
| 362 | *  | 
            ||
| 363 | * @return array  | 
            ||
| 364 | */  | 
            ||
| 365 | protected function getLDAPGroupMembers($groupDn)  | 
            ||
| 383 | |||
| 384 | /**  | 
            ||
| 385 | * Create the user in LDAP and mark as synced, provided that  | 
            ||
| 386 | * reverse sync is enabled.  | 
            ||
| 387 | *  | 
            ||
| 388 | * Set a flag "Creating" so other extensions using on*() events can  | 
            ||
| 389 | * detect whether it's in a state of being created, such as for  | 
            ||
| 390 | * synchronising with other services when a user is being created  | 
            ||
| 391 | * in LDAP for the first time.  | 
            ||
| 392 | */  | 
            ||
| 393 | public function onBeforeWrite()  | 
            ||
| 413 | |||
| 414 | /**  | 
            ||
| 415 | * Sync the local data with LDAP, and ensure local membership is also set in  | 
            ||
| 416 | * LDAP too. This writes into LDAP, provided reverse sync is enabled.  | 
            ||
| 417 | */  | 
            ||
| 418 | public function onAfterWrite()  | 
            ||
| 440 | |||
| 441 | /**  | 
            ||
| 442 |      * Triggered by {@link Member::logIn()} when successfully logged in, | 
            ||
| 443 | * this will update the Member record from AD data.  | 
            ||
| 444 | */  | 
            ||
| 445 | public function memberLoggedIn()  | 
            ||
| 451 | }  | 
            ||
| 452 | 
You can fix this by adding a namespace to your class:
When choosing a vendor namespace, try to pick something that is not too generic to avoid conflicts with other libraries.