Passed
Push — master ( 898cc7...450add )
by Thomas Mauro
03:07
created

AuthTimeChecker::supportedClaim()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 3
Code Lines 1

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 0
CRAP Score 2

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 1
eloc 1
nc 1
nop 0
dl 0
loc 3
ccs 0
cts 3
cp 0
crap 2
rs 10
c 1
b 0
f 0
1
<?php
2
3
declare(strict_types=1);
4
5
namespace TMV\OpenIdClient\ClaimChecker;
6
7
use Jose\Component\Checker\ClaimChecker;
8
use Jose\Component\Checker\InvalidClaimException;
9
10
final class AuthTimeChecker implements ClaimChecker
11
{
12
    private const CLAIM_NAME = 'auth_time';
13
14
    /** @var int */
15
    private $maxAge;
16
17
    /** @var int */
18
    private $allowedTimeDrift;
19
20
    public function __construct(int $maxAge, int $allowedTimeDrift = 0)
21
    {
22
        $this->maxAge = $maxAge;
23
        $this->allowedTimeDrift = $allowedTimeDrift;
24
    }
25
26
    /**
27
     * {@inheritdoc}
28
     */
29
    public function checkClaim($value): void
30
    {
31
        if (! \is_int($value)) {
32
            throw new InvalidClaimException('"auth_time" must be an integer.', self::CLAIM_NAME, $value);
33
        }
34
35
        if ($value + $this->maxAge < \time() - $this->allowedTimeDrift) {
36
            throw new InvalidClaimException('Too much time has elapsed since the last End-User authentication.', self::CLAIM_NAME, $value);
37
        }
38
    }
39
40
    public function supportedClaim(): string
41
    {
42
        return self::CLAIM_NAME;
43
    }
44
}
45