Some updates:
[core.git] / framework / main / classes / filter / verifier / class_GraphicalCodeCaptchaVerifierFilter.php
1 <?php
2 // Own namespace
3 namespace Org\Mxchange\CoreFramework\Filter\Verifier\Captcha;
4
5 // Import framework stuff
6 use Org\Mxchange\CoreFramework\Factory\ObjectFactory;
7 use Org\Mxchange\CoreFramework\Filter\BaseFilter;
8 use Org\Mxchange\CoreFramework\Filter\Filterable;
9 use Org\Mxchange\CoreFramework\Request\Requestable;
10 use Org\Mxchange\CoreFramework\Response\Responseable;
11
12 /**
13  * A concrete filter for validating code graphical CAPTCHAs with hashes
14  *
15  * @author              Roland Haeder <webmaster@shipsimu.org>
16  * @version             0.0.0
17 <<<<<<< HEAD:framework/main/classes/filter/verifier/class_GraphicalCodeCaptchaVerifierFilter.php
18  * @copyright   Copyright (c) 2007, 2008 Roland Haeder, 2009 - 2017 Core Developer Team
19 =======
20  * @copyright   Copyright (c) 2007, 2008 Roland Haeder, 2009 - 2016 Core Developer Team
21 >>>>>>> Some updates::inc/main/classes/filter/verifier/class_GraphicalCodeCaptchaVerifierFilter.php
22  * @license             GNU GPL 3.0 or any newer version
23  * @link                http://www.shipsimu.org
24  *
25  * This program is free software: you can redistribute it and/or modify
26  * it under the terms of the GNU General Public License as published by
27  * the Free Software Foundation, either version 3 of the License, or
28  * (at your option) any later version.
29  *
30  * This program is distributed in the hope that it will be useful,
31  * but WITHOUT ANY WARRANTY; without even the implied warranty of
32  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
33  * GNU General Public License for more details.
34  *
35  * You should have received a copy of the GNU General Public License
36  * along with this program. If not, see <http://www.gnu.org/licenses/>.
37  */
38 class GraphicalCodeCaptchaVerifierFilter extends BaseFilter implements Filterable {
39         /**
40          * Protected constructor
41          *
42          * @return      void
43          */
44         protected function __construct () {
45                 // Call parent constructor
46                 parent::__construct(__CLASS__);
47         }
48
49         /**
50          * Creates an instance of this filter class
51          *
52          * @return      $filterInstance         An instance of this filter class
53          */
54         public static final function createGraphicalCodeCaptchaVerifierFilter () {
55                 // Get a new instance
56                 $filterInstance = new GraphicalCodeCaptchaVerifierFilter();
57
58                 // Return the instance
59                 return $filterInstance;
60         }
61
62         /**
63          * Executes the filter with given request and response objects
64          *
65          * @param       $requestInstance        An instance of a class with an Requestable interface
66          * @param       $responseInstance       An instance of a class with an Responseable interface
67          * @return      void
68          * @throws      FilterChainException    If this filter fails to operate
69          */
70         public function execute (Requestable $requestInstance, Responseable $responseInstance) {
71                 // Is the form set?
72                 if (($requestInstance->getRequestElement('command') !== 'do_form') ||  (!$requestInstance->isRequestElementSet('form'))) {
73                         // Required field not set
74                         $requestInstance->requestIsValid(false);
75
76                         // Add fatal message
77                         $responseInstance->addFatalMessage('command_form_invalid');
78
79                         // Skip further processing
80                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
81                 } // END - if
82
83                 // Create config entry
84                 $configKey = sprintf('%s_captcha_secured',
85                         $requestInstance->getRequestElement('form')
86                 );
87
88                 // Is the CAPTCHA enabled?
89                 if ($this->getConfigInstance()->getConfigEntry($configKey) != 'Y') {
90                         // Not enabled, so don't check
91                         return;
92                 } // END - if
93
94                 // Get the captcha code
95                 $captchaCode = $requestInstance->getRequestElement('c_code');
96
97                 // Is this set?
98                 if (is_null($captchaCode)) {
99                         // Not set so request is invalid
100                         $requestInstance->requestIsValid(false);
101
102                         // Add fatal message
103                         $responseInstance->addFatalMessage('captcha_code_unset');
104
105                         // Skip further processing
106                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
107                 } elseif (empty($captchaCode)) {
108                         // Empty value so request is invalid
109                         $requestInstance->requestIsValid(false);
110
111                         // Add fatal message
112                         $responseInstance->addFatalMessage('captcha_code_empty');
113
114                         // Skip further processing
115                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
116                 }
117
118                 // Get the hash as well
119                 $captchaHash = $requestInstance->getRequestElement('hash');
120
121                 // Is this set?
122                 if (is_null($captchaHash)) {
123                         // Not set so request is invalid
124                         $requestInstance->requestIsValid(false);
125
126                         // Add fatal message
127                         $responseInstance->addFatalMessage('captcha_hash_unset');
128
129                         // Skip further processing
130                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
131                 } elseif (empty($captchaHash)) {
132                         // Empty value so request is invalid
133                         $requestInstance->requestIsValid(false);
134
135                         // Add fatal message
136                         $responseInstance->addFatalMessage('captcha_hash_empty');
137
138                         // Skip further processing
139                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
140                 }
141
142                 // Now, both are set hash the given one. First get a crypto instance
143                 $cryptoInstance = ObjectFactory::createObjectByConfiguredName('crypto_class');
144
145                 // Then hash the code
146                 $hashedCode = $cryptoInstance->hashString($captchaCode, $captchaHash);
147
148                 // Is this CAPTCHA valid?
149                 if ($hashedCode != $captchaHash) {
150                         // Not the same so request is invalid
151                         $requestInstance->requestIsValid(false);
152
153                         // Add fatal message
154                         $responseInstance->addFatalMessage('captcha_hash_mismatch');
155
156                         // Skip further processing
157                         throw new FilterChainException($this, self::EXCEPTION_FILTER_CHAIN_INTERCEPTED);
158                 } // END - not the same!
159         }
160
161 }