From 26229c110fb92646b36c7b2f48ac7518fd3810a5 Mon Sep 17 00:00:00 2001 From: George Halkiadakis Date: Fri, 17 Mar 2023 02:19:27 +0200 Subject: set algorithns for user authentication and authorization --- html/app/controllers/Auth.php | 196 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 196 insertions(+) create mode 100644 html/app/controllers/Auth.php (limited to 'html/app/controllers') diff --git a/html/app/controllers/Auth.php b/html/app/controllers/Auth.php new file mode 100644 index 0000000..c75f979 --- /dev/null +++ b/html/app/controllers/Auth.php @@ -0,0 +1,196 @@ +POST['email']); + + // if no user exists, return false + if ($record === false) return false; + + // create a user object + $user = (new User()) + ->setUserName($record['email']) + ->setPassword($record['password']) + ->setRoles(json_decode($record['roles'])) + ->setEnabled($record['active']); + + // let user manager to validate user credentials + $userManager = new UserManager(); + + if ($userManager->isPasswordValid($user, $req->POST['password'])) { + + // login OK, set Token in session + $userManager->createUserToken($user); + + } else { + return false; + } + } + + + /** register + * + * registers new user + * + */ + public static function register() + { + $userManager = new UserManager(); + $req = Registry::get('REQUEST'); + + // create a salted password hash + $password = $userManager->cryptPassword($req->POST['password']); + + $user = (new User()) + ->setUserName($req->POST['username']) + ->setPassword($password) + ->setRoles(['ROLE_USER']); + + // TODO: + // store user to database + + $userManager->createUserToken($user); + } + + + + public static function logout() + { + $userManager = new UserManager(); + $userManager->logout(); + } + + + + /** isGranted( ROLE ) + * + * checks if the user is granted (some of) the specified role(s) + * to access the source + * + * NOTE: + * if no roles are specified then user is granted + * (because every user is granted the 'no-role') + * + * @param $roles (array): array of roles to check (if any is granted) + * + */ + public static function isGranted($roles = []) + { + // no role required ? user is granted access + if ($roles == []) return true; + + // else, UserManager knows if user isGranted + $userManager = new UserManager(); + if ($userManager->isGranted($roles)) { + return true; + + } else { + return false; + } + } + + + /** hasPermition( PERMIT ) + * + * checks if the user owns the specified permition + * to access the source + * + */ + public static function hasPermition($permit = []) + { + if ($permit == []) return true; + } + + + /** isAuthenticated() + * + * chechs if the user's roles and permitions + * satisfy the specified requirements + * to access the source + * + * @param $requirements (array of rules-array) + * + * example: + * [ + * [ + * role => ['editor','designer'] + * permition => ['10', '12', '18'] + * ], + * [ + * role => ['admin' , 'developερ'] + * ], + * [ + * permition => [ 3 ] + * ] + * ] + * + * defines (and parses to) a requirements rule of: + * [ + * user should be editor or designer + * and have permition 10 or 12 or 18 + * ] + * OR + * [ + * user should be an administratoe or developer + * ] + * OR + * [ + * user should have permition #3 + * ] + * + * + */ + public static function isAuthorized($requirements) + { + $authorized = false; + foreach($requirements as $required) { + if ( (self::isGranted($required['role'] ?? [])) + && (self::hasPermition($required['permition'] ?? [])) ) { + $authorized = true; + } + } + return $authorized; + } + + + + + public static function forgot_pass() + { + } + + + + public static function validate_otp() + { + } + + + +} + + -- cgit v1.2.3