Total Complexity | 5 |
Total Lines | 33 |
Duplicated Lines | 0 % |
Coverage | 0% |
Changes | 1 | ||
Bugs | 0 | Features | 0 |
1 | <?php |
||
10 | final class AuthTimeChecker implements ClaimChecker |
||
11 | { |
||
12 | private const CLAIM_NAME = 'auth_time'; |
||
13 | |||
14 | /** @var int */ |
||
15 | private $maxAge; |
||
16 | |||
17 | /** @var int */ |
||
18 | private $allowedTimeDrift; |
||
19 | |||
20 | public function __construct(int $maxAge, int $allowedTimeDrift = 0) |
||
21 | { |
||
22 | $this->maxAge = $maxAge; |
||
23 | $this->allowedTimeDrift = $allowedTimeDrift; |
||
24 | } |
||
25 | |||
26 | /** |
||
27 | * {@inheritdoc} |
||
28 | */ |
||
29 | public function checkClaim($value): void |
||
30 | { |
||
31 | if (! \is_int($value)) { |
||
32 | throw new InvalidClaimException('"auth_time" must be an integer.', self::CLAIM_NAME, $value); |
||
33 | } |
||
34 | |||
35 | if ($value + $this->maxAge < \time() - $this->allowedTimeDrift) { |
||
36 | throw new InvalidClaimException('Too much time has elapsed since the last End-User authentication.', self::CLAIM_NAME, $value); |
||
37 | } |
||
38 | } |
||
39 | |||
40 | public function supportedClaim(): string |
||
43 | } |
||
44 | } |
||
45 |