3a123427a76ad3dee257457fbb66f5f1192a7371
[core.git] / framework / main / classes / filter / verifier / class_GraphicalCodeCaptchaVerifierFilter.php
1 <?php
2 // Own namespace
3 namespace Org\Mxchange\CoreFramework\Filter\Verifier\Captcha;
4
5 // Import framework stuff
6 use Org\Mxchange\CoreFramework\Factory\ObjectFactory;
7 use Org\Mxchange\CoreFramework\Filter\BaseFilter;
8 use Org\Mxchange\CoreFramework\Filter\Filterable;
9 use Org\Mxchange\CoreFramework\Request\Requestable;
10 use Org\Mxchange\CoreFramework\Response\Responseable;
11
12 /**
13  * A concrete filter for validating code graphical CAPTCHAs with hashes
14  *
15  * @author              Roland Haeder <webmaster@shipsimu.org>
16  * @version             0.0.0
17  * @copyright   Copyright (c) 2007, 2008 Roland Haeder, 2009 - 2017 Core Developer Team
18  * @license             GNU GPL 3.0 or any newer version
19  * @link                http://www.shipsimu.org
20  *
21  * This program is free software: you can redistribute it and/or modify
22  * it under the terms of the GNU General Public License as published by
23  * the Free Software Foundation, either version 3 of the License, or
24  * (at your option) any later version.
25  *
26  * This program is distributed in the hope that it will be useful,
27  * but WITHOUT ANY WARRANTY; without even the implied warranty of
28  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
29  * GNU General Public License for more details.
30  *
31  * You should have received a copy of the GNU General Public License
32  * along with this program. If not, see <http://www.gnu.org/licenses/>.
33  */
34 class GraphicalCodeCaptchaVerifierFilter extends BaseFilter implements Filterable {
35         /**
36          * Protected constructor
37          *
38          * @return      void
39          */
40         protected function __construct () {
41                 // Call parent constructor
42                 parent::__construct(__CLASS__);
43         }
44
45         /**
46          * Creates an instance of this filter class
47          *
48          * @return      $filterInstance         An instance of this filter class
49          */
50         public static final function createGraphicalCodeCaptchaVerifierFilter () {
51                 // Get a new instance
52                 $filterInstance = new GraphicalCodeCaptchaVerifierFilter();
53
54                 // Return the instance
55                 return $filterInstance;
56         }
57
58         /**
59          * Executes the filter with given request and response objects
60          *
61          * @param       $requestInstance        An instance of a class with an Requestable interface
62          * @param       $responseInstance       An instance of a class with an Responseable interface
63          * @return      void
64          * @throws      FilterChainException    If this filter fails to operate
65          */
66         public function execute (Requestable $requestInstance, Responseable $responseInstance) {
67                 // Is the form set?
68                 if (($requestInstance->getRequestElement('command') !== 'do_form') ||  (!$requestInstance->isRequestElementSet('form'))) {
69                         // Required field not set
70                         $requestInstance->requestIsValid(false);
71
72                         // Add fatal message
73                         $responseInstance->addFatalMessage('command_form_invalid');
74
75                         // Skip further processing
76                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
77                 } // END - if
78
79                 // Create config entry
80                 $configKey = sprintf('%s_captcha_secured',
81                         $requestInstance->getRequestElement('form')
82                 );
83
84                 // Is the CAPTCHA enabled?
85                 if ($this->getConfigInstance()->getConfigEntry($configKey) != 'Y') {
86                         // Not enabled, so don't check
87                         return;
88                 } // END - if
89
90                 // Get the captcha code
91                 $captchaCode = $requestInstance->getRequestElement('c_code');
92
93                 // Is this set?
94                 if (is_null($captchaCode)) {
95                         // Not set so request is invalid
96                         $requestInstance->requestIsValid(false);
97
98                         // Add fatal message
99                         $responseInstance->addFatalMessage('captcha_code_unset');
100
101                         // Skip further processing
102                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
103                 } elseif (empty($captchaCode)) {
104                         // Empty value so request is invalid
105                         $requestInstance->requestIsValid(false);
106
107                         // Add fatal message
108                         $responseInstance->addFatalMessage('captcha_code_empty');
109
110                         // Skip further processing
111                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
112                 }
113
114                 // Get the hash as well
115                 $captchaHash = $requestInstance->getRequestElement('hash');
116
117                 // Is this set?
118                 if (is_null($captchaHash)) {
119                         // Not set so request is invalid
120                         $requestInstance->requestIsValid(false);
121
122                         // Add fatal message
123                         $responseInstance->addFatalMessage('captcha_hash_unset');
124
125                         // Skip further processing
126                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
127                 } elseif (empty($captchaHash)) {
128                         // Empty value so request is invalid
129                         $requestInstance->requestIsValid(false);
130
131                         // Add fatal message
132                         $responseInstance->addFatalMessage('captcha_hash_empty');
133
134                         // Skip further processing
135                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
136                 }
137
138                 // Now, both are set hash the given one. First get a crypto instance
139                 $cryptoInstance = ObjectFactory::createObjectByConfiguredName('crypto_class');
140
141                 // Then hash the code
142                 $hashedCode = $cryptoInstance->hashString($captchaCode, $captchaHash);
143
144                 // Is this CAPTCHA valid?
145                 if ($hashedCode != $captchaHash) {
146                         // Not the same so request is invalid
147                         $requestInstance->requestIsValid(false);
148
149                         // Add fatal message
150                         $responseInstance->addFatalMessage('captcha_hash_mismatch');
151
152                         // Skip further processing
153                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
154                 } // END - not the same!
155         }
156
157 }