POST['email']); // if no user exists, return false if ($record === false) return false; // create a user object $user = (new User()) ->setUserName($record['email']) ->setPassword($record['password']) ->setRoles(json_decode($record['roles'])) ->setEnabled($record['active']); // let user manager to validate user credentials $userManager = new UserManager(); if ($userManager->isPasswordValid($user, $req->POST['password'])) { // login OK, set Token in session $userManager->createUserToken($user); } else { return false; } } /** register * * registers new user * */ public static function register() { $userManager = new UserManager(); $req = Registry::get('REQUEST'); // create a salted password hash $password = $userManager->cryptPassword($req->POST['password']); $user = (new User()) ->setUserName($req->POST['username']) ->setPassword($password) ->setRoles(['ROLE_USER']); // TODO: // store user to database $userManager->createUserToken($user); } public static function logout() { $userManager = new UserManager(); $userManager->logout(); } /** isGranted( ROLE ) * * checks if the user is granted (some of) the specified role(s) * to access the source * * NOTE: * if no roles are specified then user is granted * (because every user is granted the 'no-role') * * @param $roles (array): array of roles to check (if any is granted) * */ public static function isGranted($roles = []) { // no role required ? user is granted access if ($roles == []) return true; // else, UserManager knows if user isGranted $userManager = new UserManager(); if ($userManager->isGranted($roles)) { return true; } else { return false; } } /** hasPermition( PERMIT ) * * checks if the user owns the specified permition * to access the source * */ public static function hasPermition($permit = []) { if ($permit == []) return true; } /** isAuthenticated() * * chechs if the user's roles and permitions * satisfy the specified requirements * to access the source * * @param $requirements (array of rules-array) * * example: * [ * [ * role => ['editor','designer'] * permition => ['10', '12', '18'] * ], * [ * role => ['admin' , 'developερ'] * ], * [ * permition => [ 3 ] * ] * ] * * defines (and parses to) a requirements rule of: * [ * user should be editor or designer * and have permition 10 or 12 or 18 * ] * OR * [ * user should be an administratoe or developer * ] * OR * [ * user should have permition #3 * ] * * */ public static function isAuthorized($requirements) { $authorized = false; foreach($requirements as $required) { if ( (self::isGranted($required['role'] ?? [])) && (self::hasPermition($required['permition'] ?? [])) ) { $authorized = true; } } return $authorized; } public static function forgot_pass() { } public static function validate_otp() { } }