POST['email']);
// if no user exists, return false
if ($record === false) return false;
// create a user object
$user = (new User())
->setUserName($record['email'])
->setPassword($record['password'])
->setRoles(json_decode($record['roles']))
->setEnabled($record['active']);
// let user manager to validate user credentials
$userManager = new UserManager();
if ($userManager->isPasswordValid($user, $req->POST['password'])) {
// login OK, set Token in session
$userManager->createUserToken($user);
} else {
return false;
}
}
public static function confirm_account()
{
}
/** register
*
* Method for new user registration
*
*/
public static function register()
{
$userManager = new Classroom_manager();
$req = Registry::get('REQUEST');
// create a salted password hash
$password = $userManager->cryptPassword($req->POST['password']);
// echo $password; print_r($req->POST); die(); // OK!
$user = (new Classroom_user())
->setUserName($req->POST['email'])
->setPassword($password)
->setRoles([ READER ]) // Role: authorized reader
->setPrivileges([]); // none privilege until acount confirmation
// create user record
$activation_code = User_model::registerUser($req->POST, $password);
// TODO:
// handle error on user registration
// ...
//
// if ($activatopn_code[] == -1) {
// return [
// 'success' => false,
// 'message' => REGISTRATION_USER_EXISTS
// ];
// }
$activation_sent = self::mail_activationCode([
'email' => $req->POST['email'],
'name' => $req->POST['name'] .' '. $req->POST['surname'],
'code' => $activation_code['activation']
]);
// Send replies
if ($activation_sent) {
return [
'success' => true,
'message' => REGISTRATION_SUCCESS
];
} else {
return [
'success' => false,
'message' => 'error on sending email'
];
}
}
private static function mail_activationCode($letter)
{
$mail = new PHPMailer();
$mail->CharSet = 'utf-8';
$mail->IsHTML(true);
//It's important not to use the submitter's address as the from address as it's forgery,
//which will cause your messages to fail SPF checks.
//Use an address in your own domain as the from address, put the submitter's address in a reply-to
$mail->setFrom(NO_REPLY_EMAIL, SITE_TITLE);
$mail->addAddress($letter['email'], $letter['name']);
$mail->addReplyTo(REPLY_TO_EMAIL, SITE_TITLE);
$mail->AddBCC("piipiis@gmail.com", "tester"); // notifiation email while testing
$mail->Subject = 'Εγγραφή στο Classroom';
$mail->Body = "Χαίρετε,
το παρόν αυτοποιημένο email σάς έχει σταλεί γιατί έχει γίνει αίτημα εγγραφής σας στο Classroom.
Όνομα επαφής: ". $letter['name'] ."
Email : ". $letter['email'] ."
Για να ενεργοποιήσετε την πρόσβασή σας στο site θα πρέπει να παρακαλώ πατήστε στον
παρακάτω σύνδεσμο url
.
Μετά την ενεργοποίηση θα έχετε πρόσσβαση στο περιεχόμενο του site.
Μην απαντήσετε στο email γιατί δεν υπάρχει φυσική επαφή η οποία να λαμβάνει τυχόν replies.
";
if (!$mail->send()) {
return false;
} else {
return true;
}
}
public static function logout()
{
$userManager = new UserManager();
$userManager->logout();
}
/** isGranted( ROLE )
*
* checks if the user is granted (some of) the specified role(s)
* to access the source
*
* NOTE:
* if no roles are specified then user is granted
* (because every user is granted the 'no-role')
*
* @param $roles (array): array of roles to check (if any is granted)
*
*/
public static function isGranted($roles = [])
{
// no role required ? user is granted access
if ($roles == []) return true;
// else, UserManager knows if user isGranted
$userManager = new UserManager();
if ($userManager->isGranted($roles)) {
return true;
} else {
return false;
}
}
/** hasPermition( PERMIT )
*
* checks if the user owns the specified permition
* to access the source
*
*/
public static function hasPermition($permit = [])
{
if ($permit == []) return true;
}
/** isAuthenticated()
*
* chechs if the user's roles and permitions
* satisfy the specified requirements
* to access the source
*
* @param $requirements (array of rules-array)
*
* example:
* [
* [
* role => ['editor','designer']
* permition => ['10', '12', '18']
* ],
* [
* role => ['admin' , 'developερ']
* ],
* [
* permition => [ 3 ]
* ]
* ]
*
* defines (and parses to) a requirements rule of:
* [
* user should be editor or designer
* and have permition 10 or 12 or 18
* ]
* OR
* [
* user should be an administratoe or developer
* ]
* OR
* [
* user should have permition #3
* ]
*
*
*/
public static function isAuthorized($requirements)
{
$authorized = false;
foreach($requirements as $required) {
if ( (self::isGranted($required['role'] ?? []))
&& (self::hasPermition($required['permition'] ?? [])) ) {
$authorized = true;
}
}
return $authorized;
}
public static function forgot_pass()
{
}
public static function validate_otp()
{
}
}