summaryrefslogtreecommitdiff
path: root/public/app/controllers/Auth.php
diff options
context:
space:
mode:
Diffstat (limited to 'public/app/controllers/Auth.php')
-rw-r--r--public/app/controllers/Auth.php280
1 files changed, 101 insertions, 179 deletions
diff --git a/public/app/controllers/Auth.php b/public/app/controllers/Auth.php
index 4b3dcfb..118b4d0 100644
--- a/public/app/controllers/Auth.php
+++ b/public/app/controllers/Auth.php
@@ -5,8 +5,9 @@ use Registry;
use Render;
// user classes and models
-use app\extends\Classroom_user;
-use app\extends\Classroom_manager;
+use app\controllers\JsonToForm;
+use app\extends\App_user;
+use app\extends\App_manager;
use app\models\Access_model;
use app\extends\SendMail_service;
@@ -37,50 +38,40 @@ class Auth {
// user is valid; check user password
// create a user object
- $user = (new Classroom_user())
+ $user = (new App_user())
->setID($record['id'])
+ ->setSex( ($record['prefix'] == 'η') ? 2 : 1 )
->setUserName($record['email'])
->setName($record['first_name'] .' '. $record['last_name'])
->setPassword($record['password'])
+ ->setRoles([ $record['role_id'] ]) // roles is an array
->setEnabled($record['active']);
+
// let user manager to validate user credentials
- $userManager = new Classroom_manager();
+ $userManager = new App_manager();
if ($userManager->isPasswordValid($user, $req->POST['password'])) {
- // get user's security attributes
- $attributes = Access_model::getUser($record['id']);
- $roles = json_decode($attributes['Roles_json']);
- $user
- ->setRoles($roles)
- ->setPrivileges(
- array_merge(
- json_decode($attributes['RootPrivileges_json']),
- self::merge_lists_array(
- json_decode($attributes['SubPrivileges_json'])
- )
- )
- );
-
// regeneration session ID (prevent session fixation)
+ session_unset(); // unset $_SESSION variable for the run-time
+ session_destroy(); // destroy session data in storage before continue
+ session_start();
session_regenerate_id();
+
// set cookie for connected user
setcookie(
- 'cluser',
+ CONNECTION_COOKIE,
'connected;'. $user->getName(),
- time()+60*60*8, // 8 hours
+ time()+60*60*10, // 10 hours
'/'
);
-
- // check if admin (and redirect differently)
- $is_admin = (!empty(array_intersect([1,2,3], $roles)));
-
+
// login OK, set Token in session
$userManager->createUserToken($user);
return [
'success' => true,
- 'goto' => $is_admin ? '/admin/lessons' : '/user/profile',
+ 'goto' => '/admin/panel'
];
} else {
@@ -89,33 +80,27 @@ class Auth {
}
- /**
- * merges an array of lists to one list
- */
- private static function merge_lists_array( $list )
- {
- $current = [];
- foreach($list as $sublist) {
- $current = array_merge($current, $sublist);
- }
- return $current;
- }
-
-
/** activate
- * resolves a call like: /account/activate?ticket=ca42d68cfba5fbbafeacc010b8e3a551
+ * resolves call POST:/account/activate
+ *
+ * @param void : all parametres passed via request->POST
*/
public static function activate()
{
$req = Registry::get('REQUEST');
+ // print_r($req->POST); die();
- // get the record of the target user
- $check = Access_model::activate($req->GET['ticket']);
+ // create a salted password hash
+ $userManager = new App_manager();
+ $password = $userManager->cryptPassword($req->POST['password']);
- if ($check == true) {
+ // acivate target user and set password
+ $check = Access_model::activate_set_password($req->POST, $password);
+
+ if ($check != 0) {
Render::view('/error/general', [
'title' => ACCOUNT_ACTIVATED_TITLE,
- 'message' => ACCOUNT_ACTIVATED_MESSAGE
+ 'message' => ACCOUNT_ACTIVATED_MESSAGE . '<br>(msg code: '. $check .')'
]);
} else {
@@ -127,64 +112,72 @@ class Auth {
}
- /** register
+
+ /** invitation
+ *
+ * setups and renders the form for a certain invitation
+ *
+ * NOTE:
+ * after form is submited, client calls Auth::activate()
*
- * Method for new user registration
+ * @param $id (string|MD5) : invitation code
*
*/
- public static function register()
+ public static function invitation($id)
{
- $userManager = new Classroom_manager();
- $req = Registry::get('REQUEST');
+ // get user from invitation number
+ $user_array = Registry::use('database')->query(
+ "SELECT * FROM user WHERE invitation = :id",
+ ['id' => $id]
+ )->getFirst();
+ if ($user_array == false) {
+ Render::view('error/404', ['moto' => 'Δεν βρέθηκε η πρόσκληση']);
+ die();
+ }
+ $user = json_decode( json_encode($user_array, JSON_UNESCAPED_UNICODE)); // user in json format
- // create a salted password hash
- $password = $userManager->cryptPassword($req->POST['password']);
+ // format form_setup to a json array
+ $form_setup = json_decode(json_encode(REGISTRATION_FORM, JSON_UNESCAPED_UNICODE));
- // echo $password; print_r($req->POST); die(); // OK!
-
- $user = (new Classroom_user())
- ->setUserName($req->POST['email'])
- ->setName($req->POST['name'] .' '. $req->POST['surname'])
- ->setPassword($password)
- ->setRoles([ READER ]) // Role: authorized reader
- ->setPrivileges([]); // none privilege until acount confirmation
-
- // create user record
- $activation_code = Access_model::registerUser($req->POST, $password);
-
- // TODO:
- // handle error on user registration
- // ...
- //
- // if ($activatopn_code[] == -1) {
- // return [
- // 'success' => false,
- // 'message' => REGISTRATION_USER_EXISTS
- // ];
- // }
-
- $send_mail = SendMail_service::send_activation_code([
- 'email' => $req->POST['email'],
- 'name' => $req->POST['name'] .' '. $req->POST['surname'],
- 'code' => $activation_code['activation']
- ]);
+ // get $key of position item inside the form_setup->form array
+ for($i=0; $i < sizeof($form_setup->form) ; $i++) {
+ if ($form_setup->form[$i]->name == 'position') { $key = $i; }
+ }
- // Send replies
- if ($send_mail) {
- return [
- 'success' => true,
- 'message' => REGISTRATION_SUCCESS
+ // prepare gendered options to position field
+ $positions = ($user->prefix != 'η')
+ ? [
+ 'Διευθυντής',
+ 'Υποδιευθυντής',
+ 'Μόνιμος Καθηγητής',
+ 'Αναπληρωτής Καθηγητής'
+ ]
+ : [
+ 'Διευθύντρια',
+ 'Υποδιευθύντρια',
+ 'Μόνιμη Καθηγήτρια',
+ 'Αναπληρώτρια Καθηγήτρια'
];
+ $gendered_position = json_decode( json_encode( $positions, JSON_UNESCAPED_UNICODE ));
- } else {
- return [
- 'success' => false,
- 'message' => 'error on sending email'
- ];
- }
+ // attach gendered options
+ $form_setup->form[$key]->options = $gendered_position;
+
+ // attach default values
+ $form_setup->defaults->values = $user;
+
+ // get Form's HTML and Jsvascript
+ $form = JsonToForm::json_form($form_setup, [
+ // pass invitation identity for security
+ ['name' => 'id', 'value' => $user->id],
+ ['name' => 'invitation', 'value' => $user->invitation]
+
+ ]);
+ Render::view('user/invitation', ['form' => $form]);
}
+
/** is_connected
* checks if the user is connected
*
@@ -192,7 +185,7 @@ class Auth {
*/
public static function is_connected()
{
- $manager = new Classroom_manager();
+ $manager = new App_manager();
if ($manager->hasUserToken()) {
// user is connected;
@@ -215,16 +208,19 @@ class Auth {
*/
public static function logout()
{
- $userManager = new Classroom_manager();
+ $userManager = new App_manager();
$userManager->logout();
// regeneration session ID (prevent session fixation)
+ session_unset(); // unset $_SESSION variable for the run-time
+ session_destroy(); // destroy session data in storage before continue
+ session_start();
session_regenerate_id();
// remove user-conected cookie
- if (isset($_COOKIE['cluser'])) {
- unset($_COOKIE['cluser']);
- setcookie('cluser', '', -1, '/');
+ if (isset($_COOKIE[CONNECTION_COOKIE])) {
+ unset($_COOKIE[CONNECTION_COOKIE]);
+ setcookie(CONNECTION_COOKIE, '', -1, '/');
return true;
} else {
@@ -233,97 +229,27 @@ class Auth {
}
-
- /** hasPermition( PERMIT )
- *
- * checks if the user owns the specified permition
- * to access the source
+ /** TODO:
*
*/
- public static function hasPermition($permit = [0])
+ public static function forgot_password()
{
- if (in_array(0, $permit)) { // permision 0 means public
- return true; // permision 0 is always granted
- }
-
- if ($user = self::is_connected() === false) { // if not connected
- return false; // then no other permition is granted
- }
-
- if ($user instanceof UserInterface) {
- return ( !empty( array_intersect($permit, $user->getPrivileges()) ) );
- }
}
- /** isAuthenticated()
- *
- * chechs if the user's roles and permitions
- * satisfy the specified requirements
- * to access the source
- *
- * @param $requirements (array of rules-array)
- *
- * example:
- * [
- * [
- * role => [2, 3]
- * permition => ['10', '12', '18']
- * ],
- * [
- * role => [1 , 4]
- * ],
- * [
- * permition => [ 3 ]
- * ]
- * ]
- *
- * defines (and parses to) a requirements rule of:
- * [
- * user should be creator or editor
- * _AND_ have permition 10 or 12 or 18
- * ]
- * OR
- * [
- * user should be an administrator or developer
- * ]
- * OR
- * [
- * user should have permition #3
- * ]
- *
+ /** TODO:
*
*/
- public static function isAuthorized($requirements)
- {
- $authorized = false;
- foreach($requirements as $required) {
-
- if (isset($required['role'])) { // if a role is required
- if ( (self::isGranted($required['role'])) // authorize both role
- && (self::hasPermition($required['permition'] ?? [ 0 ])) ) { // and permition
- // $authorized = true;
- return true;
- }
-
- } else { // else, if not is not required
- if (self::hasPermition($required['permition'] ?? [ 0 ])) { // authorize permition
- // $authorized = true;
- return true;
- }
- }
- }
- return $authorized;
- }
-
-
- public static function forgot_pass()
+ public static function validate_otp()
{
}
- public static function validate_otp()
+ /** TODO:
+ *
+ */
+ public static function reset_password()
{
}
@@ -339,7 +265,7 @@ class Auth {
*/
public static function allowRoles($allowed)
{
- $manager = new Classroom_manager();
+ $manager = new App_manager();
if ($manager->isGranted($allowed)) { // if valid, return true (continue)
return true;
@@ -361,21 +287,17 @@ class Auth {
*/
public static function hasValidRole($allowed)
{
- $manager = new Classroom_manager();
+ $manager = new App_manager();
return ($manager->isGranted($allowed));
}
public static function in_admin_group()
{
- $manager = new Classroom_manager();
+ $manager = new App_manager();
return ($manager->isGranted([1, 2, 3]));
}
}
-
-
-// NOTE:
-// check: https://netcorecloud.com/tutorials/send-an-email-via-gmail-smtp-server-using-php/ \ No newline at end of file