3 namespace Org\Mxchange\CoreFramework\Filter\User\Auth;
5 // Import framework stuff
6 use Org\Mxchange\CoreFramework\Bootstrap\FrameworkBootstrap;
7 use Org\Mxchange\CoreFramework\Factory\Object\ObjectFactory;
8 use Org\Mxchange\CoreFramework\Filter\BaseFilter;
9 use Org\Mxchange\CoreFramework\Filter\Filterable;
10 use Org\Mxchange\CoreFramework\Generic\FrameworkInterface;
11 use Org\Mxchange\CoreFramework\Loader\NoClassException;
12 use Org\Mxchange\CoreFramework\Registry\Object\ObjectRegistry;
13 use Org\Mxchange\CoreFramework\Request\Requestable;
14 use Org\Mxchange\CoreFramework\Response\Responseable;
15 use Org\Mxchange\CoreFramework\User\BaseUser;
18 * A filter for checking user permissions
20 * @author Roland Haeder <webmaster@shipsimu.org>
22 * @copyright Copyright (c) 2007, 2008 Roland Haeder, 2009 - 2023 Core Developer Team
23 * @license GNU GPL 3.0 or any newer version
24 * @link http://www.shipsimu.org
26 * This program is free software: you can redistribute it and/or modify
27 * it under the terms of the GNU General Public License as published by
28 * the Free Software Foundation, either version 3 of the License, or
29 * (at your option) any later version.
31 * This program is distributed in the hope that it will be useful,
32 * but WITHOUT ANY WARRANTY; without even the implied warranty of
33 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
34 * GNU General Public License for more details.
36 * You should have received a copy of the GNU General Public License
37 * along with this program. If not, see <http://www.gnu.org/licenses/>.
39 class UserAuthFilter extends BaseFilter implements Filterable {
40 // Exception constants
41 const EXCEPTION_AUTH_DATA_INVALID = 0x1b0;
44 * The login method we shall choose
46 private $authMethod = '';
49 * Protected constructor
53 private function __construct () {
54 // Call parent constructor
55 parent::__construct(__CLASS__);
59 * Creates an instance of this filter class
61 * @return $filterInstance An instance of this filter class
63 public static final function createUserAuthFilter () {
65 $filterInstance = new UserAuthFilter();
67 // Set default auth method
68 $filterInstance->setDefaultAuthMethod();
70 // Return the instance
71 return $filterInstance;
75 * Setter for default login method from config
79 protected function setDefaultAuthMethod () {
80 $this->authMethod = FrameworkBootstrap::getConfigurationInstance()->getConfigEntry('auth_method_class');
84 * Executes the filter with given request and response objects
86 * @param $requestInstance An instance of a class with an Requestable interface
87 * @param $responseInstance An instance of a class with an Responseable interface
89 * @throws UserAuthorizationException If the auth login was not found or if it was invalid
90 * @throws UserPasswordMismatchException If the supplied password hash does not match
91 * @throws NoClassException If the user (guest/member) class was not found
93 public function execute (Requestable $requestInstance, Responseable $responseInstance) {
94 // Then get an auth instance for checking and updating the auth cookies
95 $authInstance = ObjectFactory::createObjectByName($this->authMethod, array($responseInstance));
97 // Now, get the auth data for comparison
98 $authLogin = $authInstance->getUserAuth();
99 $authHash = $authInstance->getPasswordAuth();
101 // If one is empty stop here
102 if ((empty($authLogin)) || (empty($authHash))) {
103 // Destroy the auth data
104 $authInstance->destroyAuthData();
106 // Mark the request as invalid
107 $requestInstance->setIsRequestValid(FALSE);
110 $responseInstance->addFatalMessage('auth_data_incomplete');
113 throw new UserAuthorizationException($this, self::EXCEPTION_AUTH_DATA_INVALID);
116 // Regular user account
117 $className = FrameworkBootstrap::getConfigurationInstance()->getConfigEntry('user_class');
118 $methodName = 'createMemberByUserName';
120 // Now, try to get a user or guest instance
121 if ($authLogin == FrameworkBootstrap::getConfigurationInstance()->getConfigEntry('guest_login_user')) {
123 $className = FrameworkBootstrap::getConfigurationInstance()->getConfigEntry('guest_class');
124 $methodName = 'createGuestByUserName';
127 // Does the guest class exist?
128 if (!class_exists($className)) {
130 throw new NoClassException ([$this, $className], FrameworkInterface::EXCEPTION_CLASS_NOT_FOUND);
133 // Now try the dynamic login
134 $userInstance = call_user_func_array([$className, $methodName], [$authLogin]);
136 // Is the password correct?
137 if ($userInstance->getPasswordHash() !== $authHash) {
138 // Mismatching password
139 throw new UserPasswordMismatchException(array($this, $userInstance), BaseUser::EXCEPTION_USER_PASS_MISMATCH);
142 // Remember auth and user instances in registry
143 ObjectRegistry::getRegistry('generic')->addInstance('auth', $authInstance);
144 ObjectRegistry::getRegistry('generic')->addInstance('user', $userInstance);