| Total Complexity | 5 |
| Total Lines | 33 |
| Duplicated Lines | 0 % |
| Coverage | 0% |
| Changes | 1 | ||
| Bugs | 0 | Features | 0 |
| 1 | <?php |
||
| 10 | final class AuthTimeChecker implements ClaimChecker |
||
| 11 | { |
||
| 12 | private const CLAIM_NAME = 'auth_time'; |
||
| 13 | |||
| 14 | /** @var int */ |
||
| 15 | private $maxAge; |
||
| 16 | |||
| 17 | /** @var int */ |
||
| 18 | private $allowedTimeDrift; |
||
| 19 | |||
| 20 | public function __construct(int $maxAge, int $allowedTimeDrift = 0) |
||
| 21 | { |
||
| 22 | $this->maxAge = $maxAge; |
||
| 23 | $this->allowedTimeDrift = $allowedTimeDrift; |
||
| 24 | } |
||
| 25 | |||
| 26 | /** |
||
| 27 | * {@inheritdoc} |
||
| 28 | */ |
||
| 29 | public function checkClaim($value): void |
||
| 30 | { |
||
| 31 | if (! \is_int($value)) { |
||
| 32 | throw new InvalidClaimException('"auth_time" must be an integer.', self::CLAIM_NAME, $value); |
||
| 33 | } |
||
| 34 | |||
| 35 | if ($value + $this->maxAge < \time() - $this->allowedTimeDrift) { |
||
| 36 | throw new InvalidClaimException('Too much time has elapsed since the last End-User authentication.', self::CLAIM_NAME, $value); |
||
| 37 | } |
||
| 38 | } |
||
| 39 | |||
| 40 | public function supportedClaim(): string |
||
| 43 | } |
||
| 44 | } |
||
| 45 |