diff options
| author | George Halkiadakis <gchalkiadakis@sklavenitis.co.gr> | 2023-03-17 02:19:27 +0200 |
|---|---|---|
| committer | George Halkiadakis <gchalkiadakis@sklavenitis.co.gr> | 2023-03-17 02:19:27 +0200 |
| commit | 26229c110fb92646b36c7b2f48ac7518fd3810a5 (patch) | |
| tree | 72b2f2e0e0c789853ceb815fd5b513ad31672cac /html/app/controllers/Auth.php | |
| parent | 1e438654005bd408447dc19c8a96099d228bb1aa (diff) | |
| download | classroom-26229c110fb92646b36c7b2f48ac7518fd3810a5.tar.gz classroom-26229c110fb92646b36c7b2f48ac7518fd3810a5.tar.bz2 classroom-26229c110fb92646b36c7b2f48ac7518fd3810a5.zip | |
set algorithns for user authentication and authorization
Diffstat (limited to 'html/app/controllers/Auth.php')
| -rw-r--r-- | html/app/controllers/Auth.php | 196 |
1 files changed, 196 insertions, 0 deletions
diff --git a/html/app/controllers/Auth.php b/html/app/controllers/Auth.php new file mode 100644 index 0000000..c75f979 --- /dev/null +++ b/html/app/controllers/Auth.php @@ -0,0 +1,196 @@ +<?php + +namespace app\controllers; + +use Registry; +use UserManager; +use User; +use app\models\user\User_model; + + +/** class Auth + * + * handles user's Authentication and Authorizarion + * + */ +class Auth { + + /** login + * + * checks visitor's credentials; + * if valid, authenticates user + * + */ + public static function login() + { + $req = Registry::get('REQUEST'); + + // get the record of the target user + $record = User_model::checkUser('email', $req->POST['email']); + + // if no user exists, return false + if ($record === false) return false; + + // create a user object + $user = (new User()) + ->setUserName($record['email']) + ->setPassword($record['password']) + ->setRoles(json_decode($record['roles'])) + ->setEnabled($record['active']); + + // let user manager to validate user credentials + $userManager = new UserManager(); + + if ($userManager->isPasswordValid($user, $req->POST['password'])) { + + // login OK, set Token in session + $userManager->createUserToken($user); + + } else { + return false; + } + } + + + /** register + * + * registers new user + * + */ + public static function register() + { + $userManager = new UserManager(); + $req = Registry::get('REQUEST'); + + // create a salted password hash + $password = $userManager->cryptPassword($req->POST['password']); + + $user = (new User()) + ->setUserName($req->POST['username']) + ->setPassword($password) + ->setRoles(['ROLE_USER']); + + // TODO: + // store user to database + + $userManager->createUserToken($user); + } + + + + public static function logout() + { + $userManager = new UserManager(); + $userManager->logout(); + } + + + + /** isGranted( ROLE ) + * + * checks if the user is granted (some of) the specified role(s) + * to access the source + * + * NOTE: + * if no roles are specified then user is granted + * (because every user is granted the 'no-role') + * + * @param $roles (array): array of roles to check (if any is granted) + * + */ + public static function isGranted($roles = []) + { + // no role required ? user is granted access + if ($roles == []) return true; + + // else, UserManager knows if user isGranted + $userManager = new UserManager(); + if ($userManager->isGranted($roles)) { + return true; + + } else { + return false; + } + } + + + /** hasPermition( PERMIT ) + * + * checks if the user owns the specified permition + * to access the source + * + */ + public static function hasPermition($permit = []) + { + if ($permit == []) return true; + } + + + /** isAuthenticated() + * + * chechs if the user's roles and permitions + * satisfy the specified requirements + * to access the source + * + * @param $requirements (array of rules-array) + * + * example: + * [ + * [ + * role => ['editor','designer'] + * permition => ['10', '12', '18'] + * ], + * [ + * role => ['admin' , 'developερ'] + * ], + * [ + * permition => [ 3 ] + * ] + * ] + * + * defines (and parses to) a requirements rule of: + * [ + * user should be editor or designer + * and have permition 10 or 12 or 18 + * ] + * OR + * [ + * user should be an administratoe or developer + * ] + * OR + * [ + * user should have permition #3 + * ] + * + * + */ + public static function isAuthorized($requirements) + { + $authorized = false; + foreach($requirements as $required) { + if ( (self::isGranted($required['role'] ?? [])) + && (self::hasPermition($required['permition'] ?? [])) ) { + $authorized = true; + } + } + return $authorized; + } + + + + + public static function forgot_pass() + { + } + + + + public static function validate_otp() + { + } + + + +} + + |
