summaryrefslogtreecommitdiff
path: root/html/app/controllers
diff options
context:
space:
mode:
Diffstat (limited to 'html/app/controllers')
-rw-r--r--html/app/controllers/Auth.php196
1 files changed, 196 insertions, 0 deletions
diff --git a/html/app/controllers/Auth.php b/html/app/controllers/Auth.php
new file mode 100644
index 0000000..c75f979
--- /dev/null
+++ b/html/app/controllers/Auth.php
@@ -0,0 +1,196 @@
+<?php
+
+namespace app\controllers;
+
+use Registry;
+use UserManager;
+use User;
+use app\models\user\User_model;
+
+
+/** class Auth
+ *
+ * handles user's Authentication and Authorizarion
+ *
+ */
+class Auth {
+
+ /** login
+ *
+ * checks visitor's credentials;
+ * if valid, authenticates user
+ *
+ */
+ public static function login()
+ {
+ $req = Registry::get('REQUEST');
+
+ // get the record of the target user
+ $record = User_model::checkUser('email', $req->POST['email']);
+
+ // if no user exists, return false
+ if ($record === false) return false;
+
+ // create a user object
+ $user = (new User())
+ ->setUserName($record['email'])
+ ->setPassword($record['password'])
+ ->setRoles(json_decode($record['roles']))
+ ->setEnabled($record['active']);
+
+ // let user manager to validate user credentials
+ $userManager = new UserManager();
+
+ if ($userManager->isPasswordValid($user, $req->POST['password'])) {
+
+ // login OK, set Token in session
+ $userManager->createUserToken($user);
+
+ } else {
+ return false;
+ }
+ }
+
+
+ /** register
+ *
+ * registers new user
+ *
+ */
+ public static function register()
+ {
+ $userManager = new UserManager();
+ $req = Registry::get('REQUEST');
+
+ // create a salted password hash
+ $password = $userManager->cryptPassword($req->POST['password']);
+
+ $user = (new User())
+ ->setUserName($req->POST['username'])
+ ->setPassword($password)
+ ->setRoles(['ROLE_USER']);
+
+ // TODO:
+ // store user to database
+
+ $userManager->createUserToken($user);
+ }
+
+
+
+ public static function logout()
+ {
+ $userManager = new UserManager();
+ $userManager->logout();
+ }
+
+
+
+ /** isGranted( ROLE )
+ *
+ * checks if the user is granted (some of) the specified role(s)
+ * to access the source
+ *
+ * NOTE:
+ * if no roles are specified then user is granted
+ * (because every user is granted the 'no-role')
+ *
+ * @param $roles (array): array of roles to check (if any is granted)
+ *
+ */
+ public static function isGranted($roles = [])
+ {
+ // no role required ? user is granted access
+ if ($roles == []) return true;
+
+ // else, UserManager knows if user isGranted
+ $userManager = new UserManager();
+ if ($userManager->isGranted($roles)) {
+ return true;
+
+ } else {
+ return false;
+ }
+ }
+
+
+ /** hasPermition( PERMIT )
+ *
+ * checks if the user owns the specified permition
+ * to access the source
+ *
+ */
+ public static function hasPermition($permit = [])
+ {
+ if ($permit == []) return true;
+ }
+
+
+ /** isAuthenticated()
+ *
+ * chechs if the user's roles and permitions
+ * satisfy the specified requirements
+ * to access the source
+ *
+ * @param $requirements (array of rules-array)
+ *
+ * example:
+ * [
+ * [
+ * role => ['editor','designer']
+ * permition => ['10', '12', '18']
+ * ],
+ * [
+ * role => ['admin' , 'developερ']
+ * ],
+ * [
+ * permition => [ 3 ]
+ * ]
+ * ]
+ *
+ * defines (and parses to) a requirements rule of:
+ * [
+ * user should be editor or designer
+ * and have permition 10 or 12 or 18
+ * ]
+ * OR
+ * [
+ * user should be an administratoe or developer
+ * ]
+ * OR
+ * [
+ * user should have permition #3
+ * ]
+ *
+ *
+ */
+ public static function isAuthorized($requirements)
+ {
+ $authorized = false;
+ foreach($requirements as $required) {
+ if ( (self::isGranted($required['role'] ?? []))
+ && (self::hasPermition($required['permition'] ?? [])) ) {
+ $authorized = true;
+ }
+ }
+ return $authorized;
+ }
+
+
+
+
+ public static function forgot_pass()
+ {
+ }
+
+
+
+ public static function validate_otp()
+ {
+ }
+
+
+
+}
+
+