Compare commits
22
Commits
v0.5.0
...
cb378e20bc
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cb378e20bc | ||
|
|
6b5a711fa9 | ||
|
|
95ab77db2a | ||
|
|
d6bcbf661e | ||
|
|
de2a382cbf | ||
|
|
12ba6cde7b | ||
|
|
6c5a7c98e8 | ||
|
|
4d314bcb28 | ||
|
|
890cc225ef | ||
|
|
3c1253ee45 | ||
|
|
70bf811b1d | ||
|
|
3269151e9b | ||
|
|
1da2188bdf | ||
|
|
7cf7e04d17 | ||
|
|
0813323ac2 | ||
|
|
9114cfd96f | ||
|
|
43e9b7136e | ||
|
|
38124ef66c | ||
|
|
6ed1ab26f1 | ||
|
|
a0dc1a6049 | ||
|
|
3d28485921 | ||
|
|
27394ae555 |
@@ -0,0 +1,12 @@
|
||||
.git/
|
||||
.gitignore
|
||||
var/
|
||||
vendor/
|
||||
tests/
|
||||
.phpunit.cache/
|
||||
docs/
|
||||
*.md
|
||||
.env
|
||||
.env.test
|
||||
.env.local
|
||||
composer.phar
|
||||
@@ -0,0 +1,27 @@
|
||||
APP_ENV=test
|
||||
APP_DEBUG=0
|
||||
APP_SECRET=test_secret_key_change_me
|
||||
# fixed TOTP secret (JBSWY3DPEHPK3PXP) so functional tests can compute valid codes
|
||||
TOTP_URI='otpauth://totp/Test-TOTP?secret=JBSWY3DPEHPK3PXP'
|
||||
COOKIE_TTL=2592000
|
||||
SUBDOMAIN_REDIRECT=0
|
||||
AUTH_SUBDOMAIN=''
|
||||
IP_TTL=0
|
||||
TEAPOT=1
|
||||
BURST_COUNT=10
|
||||
BURST_TIME=30
|
||||
UPPER_COUNT=100
|
||||
UPPER_TIME=3600
|
||||
TITLE='Pre-Authentication System'
|
||||
BG_COLOR='#029386'
|
||||
FG_COLOR='#ffffff'
|
||||
ERROR_COLOR='#ffb16d'
|
||||
ID_NAME='Session ID'
|
||||
TOKEN_NAME='Authentication Token'
|
||||
SUBMIT_NAME='Submit'
|
||||
ERROR_MESSAGE='Unsuccessful login attempt'
|
||||
TEAPOT_TITLE="I'm a teapot"
|
||||
TEAPOT_MESSAGE='I refuse to brew coffee'
|
||||
TOO_MANY_TITLE='Too many requests'
|
||||
TOO_MANY_MESSAGE='Try again later'
|
||||
SHELL_VERBOSITY=0
|
||||
@@ -0,0 +1,34 @@
|
||||
name: Push Develop
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- 'main'
|
||||
- 'develop'
|
||||
|
||||
jobs:
|
||||
docker:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: Build image
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: .
|
||||
push: true
|
||||
platforms: linux/amd64,linux/arm64
|
||||
tags: |
|
||||
${{ vars.DOCKERHUB_TARGET }}:develop
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
name: Push Docker
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- '*.*.*'
|
||||
|
||||
jobs:
|
||||
docker:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: Build image
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: .
|
||||
push: true
|
||||
platforms: linux/amd64,linux/arm64
|
||||
tags: |
|
||||
${{ vars.DOCKERHUB_TARGET }}:latest
|
||||
${{ vars.DOCKERHUB_TARGET }}:${{ github.ref_name }}
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
name: Sync GitHub
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- '**'
|
||||
|
||||
jobs:
|
||||
sync:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Configure Git
|
||||
run: |
|
||||
git config --global user.name "Andrew Sync"
|
||||
git config --global user.email "sync@digitaladapt.com"
|
||||
|
||||
- name: Add GitHub Remote
|
||||
env:
|
||||
SYNC_TOKEN: ${{ secrets.SYNC_GITHUB_TOKEN }}
|
||||
SYNC_TARGET: ${{ vars.SYNC_GITHUB_TARGET }}
|
||||
run: |
|
||||
git remote add github "https://digitaladapt:${SYNC_TOKEN}@github.com/$SYNC_TARGET"
|
||||
|
||||
- name: Push Current Branch
|
||||
run: |
|
||||
git push github HEAD:${GITHUB_REF_NAME}
|
||||
|
||||
- name: Push Tags
|
||||
run: |
|
||||
git push github --tags
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
name: Tests
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- 'main'
|
||||
- 'develop'
|
||||
pull_request:
|
||||
branches:
|
||||
- 'main'
|
||||
- 'develop'
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup PHP
|
||||
uses: shivammathur/setup-php@v2
|
||||
with:
|
||||
php-version: '8.5'
|
||||
extensions: apcu, mbstring
|
||||
coverage: xdebug
|
||||
ini-values: apc.enable_cli=1
|
||||
|
||||
- name: Install dependencies
|
||||
run: composer install --prefer-dist --no-progress
|
||||
|
||||
- name: Run php-cs-fixer
|
||||
run: vendor/bin/php-cs-fixer fix --dry-run --diff
|
||||
|
||||
- name: Run tests
|
||||
run: XDEBUG_MODE=coverage vendor/bin/phpunit --coverage-text
|
||||
+16
-1
@@ -1,4 +1,4 @@
|
||||
|
||||
/.idea/
|
||||
###> symfony/framework-bundle ###
|
||||
/config/secrets/prod/prod.decrypt.private.php
|
||||
/public/bundles/
|
||||
@@ -6,3 +6,18 @@
|
||||
/vendor/
|
||||
###< symfony/framework-bundle ###
|
||||
|
||||
|
||||
###> phpunit/phpunit ###
|
||||
/phpunit.xml
|
||||
/.phpunit.cache/
|
||||
/bin/.phpunit.result.cache
|
||||
###< phpunit/phpunit ###
|
||||
|
||||
###> project-specific ###
|
||||
/config/reference.php
|
||||
###< project-specific ###
|
||||
|
||||
###> friendsofphp/php-cs-fixer ###
|
||||
/.php-cs-fixer.php
|
||||
/.php-cs-fixer.cache
|
||||
###< friendsofphp/php-cs-fixer ###
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
<?php
|
||||
|
||||
$finder = (new PhpCsFixer\Finder())
|
||||
->in(__DIR__)
|
||||
->exclude('var')
|
||||
->exclude('vendor')
|
||||
->notPath([
|
||||
'config/bundles.php',
|
||||
'config/reference.php',
|
||||
])
|
||||
;
|
||||
|
||||
return (new PhpCsFixer\Config())
|
||||
->setRules([
|
||||
'@PSR12' => true,
|
||||
])
|
||||
->setFinder($finder)
|
||||
;
|
||||
+4
-4
@@ -1,5 +1,5 @@
|
||||
# use build image, to simplify final image
|
||||
FROM php:8.4-trixie AS build
|
||||
FROM php:8.5-trixie AS build
|
||||
|
||||
# install APCu and composer
|
||||
RUN pecl install apcu && \
|
||||
@@ -12,7 +12,6 @@ RUN apt-get update && \
|
||||
ENV APP_DEBUG=0
|
||||
ENV APP_ENV=prod
|
||||
ENV APP_SHARE_DIR=/data/preauth
|
||||
ENV DEFAULT_URI='http://'
|
||||
|
||||
# load application into build image
|
||||
RUN mkdir -p /data/preauth
|
||||
@@ -32,7 +31,7 @@ RUN composer install --no-dev --optimize-autoloader
|
||||
RUN composer dump-env prod --empty
|
||||
|
||||
# start creating final image
|
||||
FROM dunglas/frankenphp:php8.4-trixie
|
||||
FROM dunglas/frankenphp:php8.5-trixie
|
||||
|
||||
# install APCu
|
||||
RUN pecl install apcu && \
|
||||
@@ -42,7 +41,6 @@ RUN pecl install apcu && \
|
||||
ENV APP_DEBUG=0
|
||||
ENV APP_ENV=prod
|
||||
ENV APP_SHARE_DIR=/data/preauth
|
||||
ENV DEFAULT_URI='http://'
|
||||
|
||||
# load application into final image
|
||||
WORKDIR /app
|
||||
@@ -53,6 +51,8 @@ COPY --from=build /app /app
|
||||
COPY ./Caddyfile /etc/frankenphp/Caddyfile
|
||||
RUN cp $PHP_INI_DIR/php.ini-production $PHP_INI_DIR/php.ini
|
||||
RUN echo 'expose_php = off' > $PHP_INI_DIR/conf.d/restrict.ini
|
||||
# console needs apc to manage cache
|
||||
RUN echo 'apc.enable_cli = on' > $PHP_INI_DIR/conf.d/console.ini
|
||||
|
||||
# app uses var folder for cache storage
|
||||
VOLUME ["/config", "/data"]
|
||||
|
||||
+499
@@ -0,0 +1,499 @@
|
||||
# Preauth — Project Roadmap
|
||||
|
||||
## Project Overview
|
||||
|
||||
Preauth is a pre-authentication gate for self-hosted services. It sits
|
||||
between a reverse proxy (Caddy's `forward_auth`) and your web service,
|
||||
requiring a TOTP code (or backup code) before traffic ever reaches the
|
||||
protected application. It is **not** a replacement for the service's own
|
||||
authentication — it's a gate that prevents outsiders from even seeing
|
||||
what service is running.
|
||||
|
||||
- **Location:** `projects/preauth/`
|
||||
- **Framework:** Symfony 7.4 (PHP ≥ 8.4)
|
||||
- **Serving:** FrankenPHP (Docker image)
|
||||
- **Cache:** Dual-layer — APCu (in-memory) + file-based persistence
|
||||
- **Auth:** TOTP (single secret) + single-use backup codes
|
||||
- **Production status:** Running in production since June 2024
|
||||
|
||||
### Current Production Use
|
||||
|
||||
| Service | Purpose |
|
||||
|-------------|--------------------------------------------------|
|
||||
| Bitwarden | Password manager — always accessible, invisible to the world |
|
||||
| Microbin | Sharing text blobs and small files across devices |
|
||||
| Gitea | Code hosting — some DNS configs must be public |
|
||||
|
||||
---
|
||||
|
||||
## Architecture
|
||||
|
||||
### Request Flow
|
||||
|
||||
```
|
||||
Client → Caddy → forward_auth → Preauth listeners (priority order) → 200/401/418
|
||||
```
|
||||
|
||||
1. **AcceptListener** (priority 99) — Checks for valid session cookie.
|
||||
If found → `200 OK` + `Remote-User` header → Caddy proxies to backend.
|
||||
2. **AllowListener** (priority 88) — If `IP_TTL` is enabled, checks for
|
||||
valid IP-based session. If found → `200 OK` + `Remote-User`.
|
||||
3. **RejectListener** (priority 77) — Rate-limiting gate. If IP has
|
||||
exceeded login attempt threshold → `418 I'm a Teapot` (or `429`).
|
||||
4. **LoginListener** (priority 66) — Detects login attempts via
|
||||
`X-Preauth` header (base64url JSON) or POST form on auth subdomain.
|
||||
Validates TOTP/backup codes through `LoginManager`.
|
||||
5. **InterceptListener** (priority 55) — Fallback: if no listener has
|
||||
set a response, either redirects to auth subdomain (central auth) or
|
||||
renders the Twig login page with a fresh nonce.
|
||||
|
||||
### Key Design Decisions
|
||||
|
||||
- **No controllers** — Entirely event-listener-driven. Clean separation
|
||||
of concerns, each listener handles one stage of the auth flow.
|
||||
- **Dual-layer cache** — APCu for fast in-memory lookups, file-based
|
||||
storage for persistence across container restarts. `MonitorCacheKeys`
|
||||
wraps the PSR-6 pool to track key changes for efficient persistence
|
||||
(only write what changed).
|
||||
- **`__Host-` prefixed cookies** — `SameSite=Strict`, `Secure`,
|
||||
`HttpOnly`. Central auth mode uses a separate `__Http-Domain-Preauth`
|
||||
cookie name (domain-scoped, no `__Host-` prefix).
|
||||
- **Nonce system** — 15-byte random nonces, single-use, 120s TTL, with
|
||||
retry-on-collision (up to 3 attempts).
|
||||
- **TOTP with 10-second leeway** — Accommodates clock drift.
|
||||
- **Backup codes** — Case-insensitive alphanumeric, single-use, stored
|
||||
in cache with year-2999 expiry. Generated via console command.
|
||||
- **Domain awareness** — `DomainManager` handles multi-part TLDs
|
||||
(`.co.uk`, `.com.au`, etc.) with a built-in TLD lookup table.
|
||||
- **Interfaces** — `LoginInterface`, `DomainInterface`,
|
||||
`BackupCodeInterface` extracted to support testing (mockable).
|
||||
|
||||
---
|
||||
|
||||
## Test Suite Status
|
||||
|
||||
### Current Results
|
||||
|
||||
| Metric | Value |
|
||||
|--------------|--------------------------------|
|
||||
| **Tests** | 222 |
|
||||
| **Assertions** | 469 |
|
||||
| **Pass** | 222 (100%) |
|
||||
| **Fail** | 0 |
|
||||
| **Errors** | 0 |
|
||||
| **Warnings** | 0 |
|
||||
| **Time** | ~0.56s (without coverage) |
|
||||
| | ~1.31s (with coverage) |
|
||||
|
||||
### Code Coverage
|
||||
|
||||
| Metric | Percentage |
|
||||
|----------|---------------------|
|
||||
| **Lines** | **100.00%** (442/442) |
|
||||
| **Methods** | **100.00%** (83/83) |
|
||||
| **Classes** | **100.00%** (21/21) |
|
||||
|
||||
Every class, method, and line in `src/` is covered.
|
||||
|
||||
### Source → Test Mapping
|
||||
|
||||
| Source File | Test File | Type |
|
||||
|------------------------------------------|----------------------------------------------------|----------|
|
||||
| `Clock.php` | `Unit/ClockTest.php` | Unit |
|
||||
| `ConfigBag.php` | `Unit/ConfigBagTest.php` | Unit |
|
||||
| `Kernel.php` | (covered via functional tests) | Functional |
|
||||
| `MonitorCacheKeys.php` | `Unit/MonitorCacheKeysTest.php` | Unit |
|
||||
| `PersistCache.php` | `Unit/PersistCacheTest.php` | Unit |
|
||||
| `Utilities.php` | `Unit/UtilitiesTest.php` | Unit |
|
||||
| `Command/GenerateBackupCodesCommand.php` | `Unit/Command/GenerateBackupCodesCommandTest.php` | Unit |
|
||||
| `Data/Payload.php` | `Unit/Data/PayloadTest.php` | Unit |
|
||||
| `Enum/Scope.php` | `Unit/Enum/ScopeTest.php` | Unit |
|
||||
| `Listener/AcceptListener.php` | `Unit/Listener/AcceptListenerTest.php` | Unit |
|
||||
| `Listener/AllowListener.php` | `Unit/Listener/AllowListenerTest.php` | Unit |
|
||||
| `Listener/InterceptListener.php` | `Unit/Listener/InterceptListenerTest.php` | Unit |
|
||||
| `Listener/LoginListener.php` | `Unit/Listener/LoginListenerTest.php` | Unit |
|
||||
| `Listener/RejectListener.php` | `Unit/Listener/RejectListenerTest.php` | Unit |
|
||||
| `Service/BackupCodeManager.php` | `Unit/Service/BackupCodeManagerTest.php` | Unit |
|
||||
| `Service/DomainManager.php` | `Unit/Service/DomainManagerTest.php` | Unit |
|
||||
| `Service/LoginManager.php` | `Unit/Service/LoginManagerTest.php` | Unit |
|
||||
| `Trait/CookieNameTrait.php` | `Unit/Trait/CookieNameTraitTest.php` | Unit |
|
||||
| `Trait/GetTotpTrait.php` | `Unit/Trait/GetTotpTraitTest.php` | Unit |
|
||||
| `Trait/HasLoggerTrait.php` | `Unit/Trait/HasLoggerTraitTest.php` | Unit |
|
||||
| `Trait/MakeNonceTrait.php` | `Unit/Trait/MakeNonceTraitTest.php` | Unit |
|
||||
| `Trait/StringTrait.php` | `Unit/Trait/StringTraitTest.php` | Unit |
|
||||
| *(All listeners + services)* | `Functional/AuthenticationFlowTest.php` | Functional |
|
||||
|
||||
### Test Quality Assessment
|
||||
|
||||
**Strengths:**
|
||||
- **100% coverage** — every line, method, and class.
|
||||
- **Well-structured test hierarchy** — Unit tests per class, functional
|
||||
tests for the full HTTP kernel flow. Two support traits
|
||||
(`TotpTestHelper`, `ListenerTestHelper`) provide reusable fixtures
|
||||
(frozen clock, deterministic TOTP, Twig environment, mock rate
|
||||
limiters).
|
||||
- **Edge cases well-covered** — ULID collision handling, nonce collision
|
||||
retries, spent nonces, invalid payloads (bad base64, non-object JSON,
|
||||
arrays, null, booleans), empty/whitespace fields, field truncation,
|
||||
multibyte characters in cache keys, multi-part TLD domain matching,
|
||||
cookie pruning on invalid sessions.
|
||||
- **Both positive and negative paths** — Every listener tests both
|
||||
success and failure scenarios.
|
||||
- **Security-conscious testing** — Backup code single-use enforcement,
|
||||
case-insensitivity, character stripping, rate limit teapot vs.
|
||||
too-many-requests, return URL validation (prevents open redirect),
|
||||
cookie security attributes.
|
||||
- **Realistic functional tests** — `AuthenticationFlowTest` goes through
|
||||
the actual Symfony kernel: fetches nonces from rendered HTML, submits
|
||||
TOTP codes, verifies cookies are set, tests the full login →
|
||||
authenticated access cycle.
|
||||
- **Smart test infrastructure** — `KernelBrowser::disableReboot()` used
|
||||
in functional tests so nonces persist across requests (matching
|
||||
production APCu behavior).
|
||||
|
||||
**Status: Test suite goal is met.** 222 tests, 100% coverage, all passing.
|
||||
|
||||
---
|
||||
|
||||
## Roadmap
|
||||
|
||||
### Phase 1 — Public but Rate-Limited Access ✦
|
||||
|
||||
**Goal:** Allow select services to be publicly accessible (no TOTP
|
||||
required) but with aggressive per-IP rate limiting to prevent bot
|
||||
traffic from overwhelming the server.
|
||||
|
||||
**Context:** The user previously made Gitea semi-public (view but no
|
||||
login), but bot traffic slowed the server and consumed all household
|
||||
bandwidth, forcing it back to fully private. The solution isn't more
|
||||
authentication — it's bandwidth/resource protection for public-facing
|
||||
services.
|
||||
|
||||
**Design:**
|
||||
|
||||
- New config variables:
|
||||
- `PUBLIC_MODE=false` — Enable public access for specific services
|
||||
- `PUBLIC_RATE_LIMIT=10` — Max requests per minute from a single IP
|
||||
on public paths
|
||||
- `PUBLIC_RATE_WINDOW=60` — Sliding window in seconds
|
||||
- `PUBLIC_BURST=20` — Allow short bursts above the sustained rate
|
||||
|
||||
- New listener: **PublicListener** (priority 95, between AcceptListener
|
||||
and AllowListener):
|
||||
- Checks if the request matches a public path pattern (configured per
|
||||
service via Caddy's `forward_auth` URI or a header like
|
||||
`X-Preauth-Public: true`).
|
||||
- If public mode is enabled for this request, applies aggressive
|
||||
per-IP rate limiting (separate from the login rate limiter).
|
||||
- If within rate limit → `200 OK` (no `Remote-User` header, or a
|
||||
`Remote-User: public` marker).
|
||||
- If over rate limit → `429 Too Many Requests` with `Retry-After`
|
||||
header.
|
||||
|
||||
- Caddy config would use different `forward_auth` snippets for public
|
||||
vs. protected services:
|
||||
```caddyfile
|
||||
# Protected service — requires TOTP
|
||||
bitwarden.example.com {
|
||||
forward_auth preauth { copy_headers Remote-User }
|
||||
reverse_proxy bitwarden:80
|
||||
}
|
||||
|
||||
# Public but rate-limited service
|
||||
git.example.com {
|
||||
forward_auth preauth/public { copy_headers Remote-User }
|
||||
reverse_proxy gitea:3000
|
||||
}
|
||||
```
|
||||
|
||||
- Consider integration with Caddy's own rate limiting as a second layer
|
||||
of defense (rate limit at the reverse proxy before traffic even hits
|
||||
preauth).
|
||||
|
||||
- [ ] Design public path detection mechanism (URI-based or header-based)
|
||||
- [ ] Implement `PublicListener` with separate rate limiter pool
|
||||
- [ ] Add config variables and defaults
|
||||
- [ ] Update Caddyfile example with public service snippet
|
||||
- [ ] Tests for public mode (within limit, over limit, burst behavior)
|
||||
- [ ] Documentation in README
|
||||
|
||||
### Phase 2 — Session Management & Audit
|
||||
|
||||
**Goal:** Give visibility into who has access and when it was granted.
|
||||
|
||||
- [ ] **Active sessions view** — Console command or simple API endpoint
|
||||
to list active sessions (cookie-based and IP-based), showing:
|
||||
- Session ID / username
|
||||
- IP address
|
||||
- First auth timestamp
|
||||
- Last seen timestamp
|
||||
- Scope (cookie vs. IP)
|
||||
- [ ] **Session revocation** — Console command to revoke a specific
|
||||
session by ID or revoke all sessions for an IP.
|
||||
- [ ] **Audit log** — Log every successful and failed authentication
|
||||
attempt to a persistent store (file-based JSONL, similar to the email
|
||||
integration's audit log):
|
||||
```json
|
||||
{
|
||||
"timestamp": "2025-01-15T14:23:01Z",
|
||||
"ip": "192.168.1.50",
|
||||
"action": "login_success",
|
||||
"username": "mom",
|
||||
"method": "totp"
|
||||
}
|
||||
```
|
||||
- [ ] Tests for all new commands and endpoints
|
||||
|
||||
### Phase 2b — Backup Code System Completion
|
||||
|
||||
**Goal:** Finish the backup code system — the core logic is solid but
|
||||
the management surface is incomplete.
|
||||
|
||||
**What already exists:**
|
||||
- ✅ `BackupCodeManager::generate()` — Creates codes, saves to cache
|
||||
with year-2999 expiry
|
||||
- ✅ `BackupCodeManager::expire()` — Deletes all `backup_` prefixed
|
||||
keys from cache
|
||||
- ✅ `BackupCodeManager::verifyAndConsume()` — Validates and marks code
|
||||
as used (sets value to `false`, keeps the key for audit trail)
|
||||
- ✅ `app:generate-backup-codes [count]` console command
|
||||
- ✅ Tests for all of the above (100% coverage)
|
||||
|
||||
**What's missing:**
|
||||
|
||||
- [ ] **`app:list-backup-codes` command** — Show backup code status:
|
||||
- Total codes generated
|
||||
- How many are still valid (unused)
|
||||
- How many have been spent (and optionally when)
|
||||
- Output format: table with status column (✅ valid / ⛔ used)
|
||||
- Note: spent codes are kept in cache with value `false`, so we can
|
||||
distinguish "used" from "never existed" — this is good design
|
||||
|
||||
- [ ] **`app:expire-backup-codes` command** — Wrap the existing
|
||||
`BackupCodeManager::expire()` method in a console command. Should:
|
||||
- Show how many codes are being expired before confirmation
|
||||
- Support `--force` flag to skip confirmation prompt
|
||||
- Call `persistCache->boot()` and `persistCache->persist()` like the
|
||||
generate command does (since `Kernel::terminate()` doesn't run in
|
||||
CLI)
|
||||
|
||||
- [ ] **Notification on backup code use** — When
|
||||
`verifyAndConsume()` consumes a backup code, fire a notification
|
||||
through configurable channels:
|
||||
- Discord webhook (we already have the `discord.sh` infrastructure)
|
||||
- ntfy
|
||||
- Email (once email integration is available)
|
||||
- Webhook (generic HTTP POST for future integrations)
|
||||
- Config variables:
|
||||
- `BACKUP_CODE_NOTIFY=discord,ntfy` — comma-separated channels
|
||||
- `BACKUP_CODE_NOTIFY_WEBHOOK=''` — generic webhook URL
|
||||
- Message should include: timestamp, IP address, username, and how
|
||||
many valid codes remain
|
||||
- Architecture: `BackupCodeManager` dispatches an event
|
||||
(e.g. `BackupCodeUsedEvent`) after consuming a code. A listener
|
||||
handles the notification dispatch. This keeps the notification
|
||||
logic out of the backup code manager itself.
|
||||
|
||||
- [ ] **Low-codes warning** — If backup codes fall below a threshold
|
||||
(e.g. 3 remaining), include a warning in the notification and/or
|
||||
surface it in the `list-backup-codes` command output
|
||||
|
||||
- [ ] Tests for all new commands and notification dispatch
|
||||
|
||||
### Phase 2c — Passkey Authentication
|
||||
|
||||
**Goal:** Add WebAuthn/FIDO2 passkey support as an alternative
|
||||
authentication method alongside TOTP and backup codes.
|
||||
|
||||
**Context:** Passkeys are the modern standard for passwordless auth.
|
||||
They're phishing-resistant (domain-bound), use biometrics or device
|
||||
PINs, and are significantly more user-friendly than typing 6-digit
|
||||
codes. For a pre-auth gate that friends and family use, passkeys would
|
||||
be a major UX improvement — especially for non-technical users who
|
||||
struggle with TOTP apps.
|
||||
|
||||
**Design considerations:**
|
||||
|
||||
- Passkeys are **per-device**, not shared secrets. Unlike TOTP (one
|
||||
secret shared with all devices), each device registers its own
|
||||
passkey. This is actually better for a family-use gate — you can
|
||||
register mom's phone separately from dad's laptop.
|
||||
|
||||
- WebAuthn requires a **challenge-response flow**:
|
||||
1. Client requests a challenge (preauth generates and stores a
|
||||
challenge nonce, similar to the existing nonce system)
|
||||
2. Browser prompts for biometric/PIN, creates a signed assertion
|
||||
3. Server verifies the assertion against the registered credential
|
||||
|
||||
- This is a **two-step flow** unlike TOTP's single-step, which means
|
||||
the login page JS and `LoginListener` need to handle an additional
|
||||
round-trip. The existing nonce + AJAX pattern in `_script.html.twig`
|
||||
is a good foundation — extend it with a "use passkey" button that
|
||||
initiates the `navigator.credentials.get()` flow.
|
||||
|
||||
- Library: `web-auth/webauthn-framework` (PHP WebAuthn library,
|
||||
Symfony bundle available). Would add registration ceremony (console
|
||||
command or initial-setup flow to register a passkey).
|
||||
|
||||
- [ ] Research `web-auth/webauthn-framework` integration with Symfony
|
||||
7.4 and FrankenPHP
|
||||
- [ ] Design passkey registration flow (console command? first-visit
|
||||
setup? separate registration endpoint?)
|
||||
- [ ] Implement challenge generation and storage (extend existing
|
||||
nonce/cache infrastructure)
|
||||
- [ ] Implement assertion verification in a new `PasskeyManager`
|
||||
service (implements a shared `AuthMethodInterface`?)
|
||||
- [ ] Add passkey option to login page JS (`navigator.credentials.get()`)
|
||||
- [ ] Handle multiple registered passkeys (per-device)
|
||||
- [ ] Console command: `app:list-passkeys` — show registered devices
|
||||
- [ ] Console command: `app:remove-passkey` — revoke a passkey
|
||||
- [ ] Config: `PASSKEY_ENABLED=false` — enable/disable passkey auth
|
||||
- [ ] Tests for registration, authentication, and revocation
|
||||
- [ ] Consider: should passkeys be a *replacement* for TOTP or an
|
||||
*alternative*? (Probably alternative — keep TOTP as fallback)
|
||||
|
||||
### Phase 3 — Multi-User Support
|
||||
|
||||
**Goal:** Support multiple TOTP users for household/family access.
|
||||
|
||||
*Note: This is a significant feature that changes the single-secret
|
||||
model. It should only be pursued if the single-secret + backup codes
|
||||
approach proves insufficient for the use case.*
|
||||
|
||||
- [ ] Multiple TOTP secrets, each with a label (e.g., "mom", "dad",
|
||||
"friend")
|
||||
- [ ] Per-user backup codes
|
||||
- [ ] Per-user session tracking (the `username` field in Payload already
|
||||
supports this — sessions are already tagged with an ID)
|
||||
- [ ] Console command to add/remove/list users
|
||||
- [ ] Consider: should the login page ask for a username, or should all
|
||||
TOTP codes be tried against all secrets? (Username is better —
|
||||
it's already in the payload.)
|
||||
- [ ] Tests for multi-user scenarios
|
||||
|
||||
### Phase 4 — Polish & Hardening
|
||||
|
||||
**Goal:** Production hardening and quality-of-life improvements.
|
||||
|
||||
- [ ] **Docker image improvements:**
|
||||
- Multi-arch builds (amd64 + arm64 for Raspberry Pi)
|
||||
- Smaller image size (alpine-based if feasible)
|
||||
- Better health check (actual endpoint, not just `curl localhost`)
|
||||
- [ ] **GitHub/Gitea repository polish:**
|
||||
- Comprehensive README with setup guide, architecture overview, and
|
||||
configuration reference
|
||||
- Contributing guidelines
|
||||
- Changelog (currently inline in README — formalise it)
|
||||
- GitHub Actions CI (run tests on push/PR, build Docker image on tag)
|
||||
- [ ] **Security review:**
|
||||
- Consider CSRF protection on the POST form login (auth subdomain)
|
||||
- Consider adding `X-Content-Type-Options: nosniff` and other security
|
||||
headers to responses
|
||||
- Review nonce entropy and cache key collision space
|
||||
- Consider session fixation protections
|
||||
- [ ] **Frontend improvements:**
|
||||
- Mobile-responsive login page audit
|
||||
- Accessibility audit (ARIA labels, keyboard navigation)
|
||||
- Dark mode (if not already — the teal background suggests it might
|
||||
already be dark-themed)
|
||||
- [ ] **Logging improvements:**
|
||||
- Structured logging (JSON format option) for easier parsing
|
||||
- Log rotation configuration
|
||||
- Debug mode documentation
|
||||
|
||||
---
|
||||
|
||||
## Feature Thoughts
|
||||
|
||||
Based on the review, here are features that might be missing or worth
|
||||
considering, keeping in mind that preauth is a **gate**, not a full
|
||||
identity provider:
|
||||
|
||||
### High Value
|
||||
|
||||
1. **Public but rate-limited mode** (Phase 1) — Directly solves the
|
||||
Gitea bot traffic problem. This is the most impactful missing
|
||||
feature.
|
||||
|
||||
2. **Passkey authentication** (Phase 2c) — Phishing-resistant,
|
||||
passwordless auth that's far more user-friendly than TOTP for
|
||||
non-technical family members. The modern standard for this kind
|
||||
of gate.
|
||||
|
||||
3. **Backup code notifications** (Phase 2b) — When a backup code is
|
||||
used, you should know about it immediately. This is a security-critical
|
||||
event — it means someone lost their device or is locked out of their
|
||||
TOTP app. Discord/ntfy/email notification should fire automatically.
|
||||
|
||||
4. **Backup code management commands** (Phase 2b) — The `generate`
|
||||
command exists, but `list` and `expire` commands are missing despite
|
||||
the underlying methods (`expire()`) already being implemented.
|
||||
|
||||
5. **Session visibility and revocation** (Phase 2) — Currently there's
|
||||
no way to see who has access or revoke a session without clearing
|
||||
the entire cache. For a security tool, this is important.
|
||||
|
||||
6. **Audit log** (Phase 2) — For a security gate, not having an audit
|
||||
trail of logins (successful and failed) is a gap. The data is logged
|
||||
at debug level, but not persisted in a queryable format.
|
||||
|
||||
### Medium Value
|
||||
|
||||
4. **Health check endpoint** — The Dockerfile has a `HEALTHCHECK` that
|
||||
just `curl`s localhost, but a dedicated `/health` endpoint that
|
||||
verifies cache connectivity would be more meaningful.
|
||||
|
||||
5. **Graceful degradation** — If the file-based cache is corrupted or
|
||||
unavailable, does preauth fail open or closed? Should be documented
|
||||
and tested. (Currently the `PersistCache` handles this in `boot()`,
|
||||
but edge cases around partial corruption could be explored.)
|
||||
|
||||
6. **Rate limit headers** — Adding `X-RateLimit-Remaining` and
|
||||
`Retry-After` headers to rate-limited responses would help legitimate
|
||||
clients back off gracefully.
|
||||
|
||||
### Lower Value (Nice to Have)
|
||||
|
||||
7. **WebSocket support** — If protected services use WebSocket
|
||||
connections, does `forward_auth` handle the upgrade handshake? This
|
||||
is likely a Caddy configuration concern, but worth documenting.
|
||||
|
||||
8. **Theming presets** — Beyond the current env-var colour config,
|
||||
preset themes or custom CSS upload could be nice for personalisation.
|
||||
|
||||
9. **TOTP secret rotation** — Console command to generate a new TOTP
|
||||
secret and invalidate all existing sessions. Useful if a device is
|
||||
lost or compromised.
|
||||
|
||||
10. **Per-service authentication policies** — Different services could
|
||||
require different authentication strength (e.g., Bitwarden requires
|
||||
TOTP + recent login, Microbin accepts any valid session). This would
|
||||
need Caddy configuration support to pass the policy to preauth.
|
||||
|
||||
---
|
||||
|
||||
## Branch Status
|
||||
|
||||
| Branch | Status | Notes |
|
||||
|--------|--------|-------|
|
||||
| `main` (0.8.1) | Production | Current stable release |
|
||||
| `kat-tests` | ✅ Ready to merge | 222 tests, 100% coverage, all passing |
|
||||
| `origin/improved-rate-limiting` | Stale | Compound sliding-window rate limiting. Already merged into main via develop. |
|
||||
| `origin/cache-persistence-improvement` | Merged (0.7.0) | Only persist changed keys. In main. |
|
||||
| `origin/remove-static-secret` | Merged | Removed static password, replaced with backup codes. In main. |
|
||||
| `origin/cleanup-cline*`, `cline-wip` | Experimental | Code cleanup attempts, not merged. |
|
||||
| `origin/add-notes` | Minor | Documentation additions. |
|
||||
|
||||
---
|
||||
|
||||
## Relationship to Other Projects
|
||||
|
||||
| Project | Integration |
|
||||
|---------|-------------|
|
||||
| MCP server | Preauth could be registered as an MCP command for session management ("revoke all sessions", "who's logged in?") |
|
||||
| Email integration | Audit log entries could be included in morning summary ("2 failed login attempts from 203.0.113.50 overnight") |
|
||||
| Discord/ntfy | Alert on backup code usage, suspicious activity (rate limit triggered, multiple failed attempts from new IP), low backup code count |
|
||||
|
||||
---
|
||||
|
||||
*Prepared by Lyra, your office-side assistant. ✨*
|
||||
+4
-2
@@ -1,7 +1,9 @@
|
||||
#!/bin/sh
|
||||
# Dev utility — builds and runs the preauth container locally.
|
||||
# Not for production use.
|
||||
|
||||
docker container rm preauth
|
||||
docker build . -t digtialadapt/preauth:dev
|
||||
docker build . -t digitaladapt/preauth:dev
|
||||
docker run --name preauth \
|
||||
-e APP_ENV=dev \
|
||||
-e APP_DEBUG=true \
|
||||
@@ -10,4 +12,4 @@ docker run --name preauth \
|
||||
-e DEFAULT_URI=http://localhost \
|
||||
-v ./var/share:/app/var/share \
|
||||
-p 8000:80 \
|
||||
digtialadapt/preauth:dev
|
||||
digitaladapt/preauth:dev
|
||||
|
||||
Executable
+4
@@ -0,0 +1,4 @@
|
||||
#!/usr/bin/env php
|
||||
<?php
|
||||
|
||||
require dirname(__DIR__).'/vendor/phpunit/phpunit/phpunit';
|
||||
+13
-6
@@ -1,20 +1,21 @@
|
||||
{
|
||||
"type": "project",
|
||||
"license": "proprietary",
|
||||
"license": "MIT",
|
||||
"minimum-stability": "stable",
|
||||
"prefer-stable": true,
|
||||
"require": {
|
||||
"php": ">=8.2",
|
||||
"php": ">=8.4",
|
||||
"ext-ctype": "*",
|
||||
"ext-iconv": "*",
|
||||
"bacon/bacon-qr-code": "^3.0",
|
||||
"runtime/frankenphp-symfony": "^0.2.0",
|
||||
"spomky-labs/otphp": "^11.3",
|
||||
"bacon/bacon-qr-code": "^3.1.1",
|
||||
"runtime/frankenphp-symfony": "^1.0.0",
|
||||
"spomky-labs/otphp": "^11.4.2",
|
||||
"symfony/cache": "7.4.*",
|
||||
"symfony/console": "7.4.*",
|
||||
"symfony/flex": "^2",
|
||||
"symfony/flex": "^2.11",
|
||||
"symfony/framework-bundle": "7.4.*",
|
||||
"symfony/mime": "7.4.*",
|
||||
"symfony/rate-limiter": "7.4.*",
|
||||
"symfony/runtime": "7.4.*",
|
||||
"symfony/twig-bundle": "7.4.*",
|
||||
"symfony/uid": "7.4.*",
|
||||
@@ -72,5 +73,11 @@
|
||||
"allow-contrib": false,
|
||||
"require": "7.4.*"
|
||||
}
|
||||
},
|
||||
"require-dev": {
|
||||
"friendsofphp/php-cs-fixer": "*",
|
||||
"phpunit/phpunit": "^13.2",
|
||||
"symfony/browser-kit": "7.4.*",
|
||||
"symfony/css-selector": "7.4.*"
|
||||
}
|
||||
}
|
||||
|
||||
Generated
+3920
-269
File diff suppressed because it is too large
Load Diff
@@ -2,38 +2,14 @@ framework:
|
||||
cache:
|
||||
app: cache.adapter.filesystem
|
||||
pools:
|
||||
noncePool:
|
||||
adapters:
|
||||
- cache.adapter.apcu
|
||||
sessionPool:
|
||||
adapters:
|
||||
- cache.adapter.apcu
|
||||
requestPool:
|
||||
adapters:
|
||||
- cache.adapter.apcu
|
||||
persistSessionPool:
|
||||
adapters:
|
||||
- cache.adapter.filesystem
|
||||
persistRequestPool:
|
||||
adapters:
|
||||
- cache.adapter.filesystem
|
||||
nonceCache:
|
||||
adapters: cache.adapter.apcu
|
||||
rateLimitCache:
|
||||
adapters: cache.adapter.apcu
|
||||
sessionCache:
|
||||
adapters: cache.adapter.apcu
|
||||
sessionStorage:
|
||||
adapters: cache.adapter.filesystem
|
||||
|
||||
# Unique name of your app: used to compute
|
||||
# stable namespaces for cache keys.
|
||||
# Unique name of your app: used to compute stable namespaces for cache keys.
|
||||
prefix_seed: digitaladapt/preauth
|
||||
|
||||
# The "app" cache stores to the filesystem by default.
|
||||
# The data in this cache should persist between deploys.
|
||||
# Other options include:
|
||||
|
||||
# Redis
|
||||
#app: cache.adapter.redis
|
||||
#default_redis_provider: redis://localhost
|
||||
|
||||
# APCu (not recommended with heavy random-write workloads
|
||||
# as memory fragmentation can cause perf issues)
|
||||
#app: cache.adapter.apcu
|
||||
|
||||
# Namespaced pools use the above "app" backend by default
|
||||
#pools:
|
||||
#my.dedicated.cache: null
|
||||
|
||||
@@ -7,12 +7,3 @@ framework:
|
||||
|
||||
# Note that the session will be started ONLY if you read or write from it.
|
||||
session: true
|
||||
|
||||
#esi: true
|
||||
#fragments: true
|
||||
|
||||
when@test:
|
||||
framework:
|
||||
test: true
|
||||
session:
|
||||
storage_factory_id: session.storage.factory.mock_file
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
framework:
|
||||
rate_limiter:
|
||||
burst:
|
||||
policy: 'sliding_window'
|
||||
limit: '%env(int:BURST_COUNT)%'
|
||||
interval: '%env(int:BURST_TIME)% seconds'
|
||||
cache_pool: 'rateLimitCache'
|
||||
upper:
|
||||
policy: 'sliding_window'
|
||||
limit: '%env(int:UPPER_COUNT)%'
|
||||
interval: '%env(int:UPPER_TIME)% seconds'
|
||||
cache_pool: 'rateLimitCache'
|
||||
login_limiter:
|
||||
policy: compound
|
||||
limiters: [burst, upper]
|
||||
@@ -1,10 +1,6 @@
|
||||
framework:
|
||||
router:
|
||||
# Configure how to generate URLs in non-HTTP contexts,
|
||||
# such as CLI commands. See
|
||||
# https://symfony.com/doc/current/routing.html
|
||||
# #generating-urls-in-commands
|
||||
default_uri: '%env(DEFAULT_URI)%'
|
||||
default_uri: 'http://localhost'
|
||||
|
||||
when@prod:
|
||||
framework:
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
framework:
|
||||
cache:
|
||||
app: cache.adapter.array
|
||||
pools:
|
||||
nonceCache:
|
||||
adapters: cache.adapter.array
|
||||
rateLimitCache:
|
||||
adapters: cache.adapter.array
|
||||
sessionCache:
|
||||
adapters: cache.adapter.array
|
||||
sessionStorage:
|
||||
adapters: cache.adapter.array
|
||||
@@ -0,0 +1,4 @@
|
||||
framework:
|
||||
test: true
|
||||
session:
|
||||
storage_factory_id: session.storage.factory.mock_file
|
||||
@@ -3,21 +3,16 @@ twig:
|
||||
strict_variables: true
|
||||
globals:
|
||||
env:
|
||||
allow_password: '%env(STATIC_SECRET_ENABLED)%'
|
||||
title: '%env(TITLE)%'
|
||||
bg_color: '%env(BG_COLOR)%'
|
||||
fg_color: '%env(FG_COLOR)%'
|
||||
error_color: '%env(ERROR_COLOR)%'
|
||||
return_field: '%env(QUERY_PREFIX)%return'
|
||||
id_field: '%env(QUERY_PREFIX)%id'
|
||||
token_field: '%env(QUERY_PREFIX)%token'
|
||||
password_field: '%env(QUERY_PREFIX)%password'
|
||||
id_name: '%env(ID_NAME)%'
|
||||
token_name: '%env(TOKEN_NAME)%'
|
||||
password_name: '%env(PASSWORD_NAME)%'
|
||||
submit_name: '%env(SUBMIT_NAME)%'
|
||||
error_message: '%env(ERROR_MESSAGE)%'
|
||||
teapot_title: '%env(TEAPOT_TITLE)%'
|
||||
teapot_message: '%env(TEAPOT_MESSAGE)%'
|
||||
too_many_title: '%env(TOO_MANY_TITLE)%'
|
||||
too_many_message: '%env(TOO_MANY_MESSAGE)%'
|
||||
debug: '%env(SHELL_VERBOSITY)%'
|
||||
|
||||
@@ -1,847 +0,0 @@
|
||||
<?php
|
||||
|
||||
// This file is auto-generated and is for apps only. Bundles SHOULD NOT rely on its content.
|
||||
|
||||
namespace Symfony\Component\DependencyInjection\Loader\Configurator;
|
||||
|
||||
/**
|
||||
* This class provides array-shapes for configuring the services and bundles of an application.
|
||||
*
|
||||
* Services declared with the config() method below are autowired and autoconfigured by default.
|
||||
*
|
||||
* This is for apps only. Bundles SHOULD NOT use it.
|
||||
*
|
||||
* Example:
|
||||
*
|
||||
* ```php
|
||||
* // config/services.php
|
||||
* namespace Symfony\Component\DependencyInjection\Loader\Configurator;
|
||||
*
|
||||
* return App::config([
|
||||
* 'services' => [
|
||||
* 'App\\' => [
|
||||
* 'resource' => '../src/',
|
||||
* ],
|
||||
* ],
|
||||
* ]);
|
||||
* ```
|
||||
*
|
||||
* @psalm-type ImportsConfig = list<string|array{
|
||||
* resource: string,
|
||||
* type?: string|null,
|
||||
* ignore_errors?: bool,
|
||||
* }>
|
||||
* @psalm-type ParametersConfig = array<string, scalar|\UnitEnum|array<scalar|\UnitEnum|array<mixed>|null>|null>
|
||||
* @psalm-type ArgumentsType = list<mixed>|array<string, mixed>
|
||||
* @psalm-type CallType = array<string, ArgumentsType>|array{0:string, 1?:ArgumentsType, 2?:bool}|array{method:string, arguments?:ArgumentsType, returns_clone?:bool}
|
||||
* @psalm-type TagsType = list<string|array<string, array<string, mixed>>> // arrays inside the list must have only one element, with the tag name as the key
|
||||
* @psalm-type CallbackType = string|array{0:string|ReferenceConfigurator,1:string}|\Closure|ReferenceConfigurator|ExpressionConfigurator
|
||||
* @psalm-type DeprecationType = array{package: string, version: string, message?: string}
|
||||
* @psalm-type DefaultsType = array{
|
||||
* public?: bool,
|
||||
* tags?: TagsType,
|
||||
* resource_tags?: TagsType,
|
||||
* autowire?: bool,
|
||||
* autoconfigure?: bool,
|
||||
* bind?: array<string, mixed>,
|
||||
* }
|
||||
* @psalm-type InstanceofType = array{
|
||||
* shared?: bool,
|
||||
* lazy?: bool|string,
|
||||
* public?: bool,
|
||||
* properties?: array<string, mixed>,
|
||||
* configurator?: CallbackType,
|
||||
* calls?: list<CallType>,
|
||||
* tags?: TagsType,
|
||||
* resource_tags?: TagsType,
|
||||
* autowire?: bool,
|
||||
* bind?: array<string, mixed>,
|
||||
* constructor?: string,
|
||||
* }
|
||||
* @psalm-type DefinitionType = array{
|
||||
* class?: string,
|
||||
* file?: string,
|
||||
* parent?: string,
|
||||
* shared?: bool,
|
||||
* synthetic?: bool,
|
||||
* lazy?: bool|string,
|
||||
* public?: bool,
|
||||
* abstract?: bool,
|
||||
* deprecated?: DeprecationType,
|
||||
* factory?: CallbackType,
|
||||
* configurator?: CallbackType,
|
||||
* arguments?: ArgumentsType,
|
||||
* properties?: array<string, mixed>,
|
||||
* calls?: list<CallType>,
|
||||
* tags?: TagsType,
|
||||
* resource_tags?: TagsType,
|
||||
* decorates?: string,
|
||||
* decoration_inner_name?: string,
|
||||
* decoration_priority?: int,
|
||||
* decoration_on_invalid?: 'exception'|'ignore'|null,
|
||||
* autowire?: bool,
|
||||
* autoconfigure?: bool,
|
||||
* bind?: array<string, mixed>,
|
||||
* constructor?: string,
|
||||
* from_callable?: CallbackType,
|
||||
* }
|
||||
* @psalm-type AliasType = string|array{
|
||||
* alias: string,
|
||||
* public?: bool,
|
||||
* deprecated?: DeprecationType,
|
||||
* }
|
||||
* @psalm-type PrototypeType = array{
|
||||
* resource: string,
|
||||
* namespace?: string,
|
||||
* exclude?: string|list<string>,
|
||||
* parent?: string,
|
||||
* shared?: bool,
|
||||
* lazy?: bool|string,
|
||||
* public?: bool,
|
||||
* abstract?: bool,
|
||||
* deprecated?: DeprecationType,
|
||||
* factory?: CallbackType,
|
||||
* arguments?: ArgumentsType,
|
||||
* properties?: array<string, mixed>,
|
||||
* configurator?: CallbackType,
|
||||
* calls?: list<CallType>,
|
||||
* tags?: TagsType,
|
||||
* resource_tags?: TagsType,
|
||||
* autowire?: bool,
|
||||
* autoconfigure?: bool,
|
||||
* bind?: array<string, mixed>,
|
||||
* constructor?: string,
|
||||
* }
|
||||
* @psalm-type StackType = array{
|
||||
* stack: list<DefinitionType|AliasType|PrototypeType|array<class-string, ArgumentsType|null>>,
|
||||
* public?: bool,
|
||||
* deprecated?: DeprecationType,
|
||||
* }
|
||||
* @psalm-type ServicesConfig = array{
|
||||
* _defaults?: DefaultsType,
|
||||
* _instanceof?: InstanceofType,
|
||||
* ...<string, DefinitionType|AliasType|PrototypeType|StackType|ArgumentsType|null>
|
||||
* }
|
||||
* @psalm-type ExtensionType = array<string, mixed>
|
||||
* @psalm-type FrameworkConfig = array{
|
||||
* secret?: scalar|null,
|
||||
* http_method_override?: bool, // Set true to enable support for the '_method' request parameter to determine the intended HTTP method on POST requests. // Default: false
|
||||
* allowed_http_method_override?: list<string>|null,
|
||||
* trust_x_sendfile_type_header?: scalar|null, // Set true to enable support for xsendfile in binary file responses. // Default: "%env(bool:default::SYMFONY_TRUST_X_SENDFILE_TYPE_HEADER)%"
|
||||
* ide?: scalar|null, // Default: "%env(default::SYMFONY_IDE)%"
|
||||
* test?: bool,
|
||||
* default_locale?: scalar|null, // Default: "en"
|
||||
* set_locale_from_accept_language?: bool, // Whether to use the Accept-Language HTTP header to set the Request locale (only when the "_locale" request attribute is not passed). // Default: false
|
||||
* set_content_language_from_locale?: bool, // Whether to set the Content-Language HTTP header on the Response using the Request locale. // Default: false
|
||||
* enabled_locales?: list<scalar|null>,
|
||||
* trusted_hosts?: list<scalar|null>,
|
||||
* trusted_proxies?: mixed, // Default: ["%env(default::SYMFONY_TRUSTED_PROXIES)%"]
|
||||
* trusted_headers?: list<scalar|null>,
|
||||
* error_controller?: scalar|null, // Default: "error_controller"
|
||||
* handle_all_throwables?: bool, // HttpKernel will handle all kinds of \Throwable. // Default: true
|
||||
* csrf_protection?: bool|array{
|
||||
* enabled?: scalar|null, // Default: null
|
||||
* stateless_token_ids?: list<scalar|null>,
|
||||
* check_header?: scalar|null, // Whether to check the CSRF token in a header in addition to a cookie when using stateless protection. // Default: false
|
||||
* cookie_name?: scalar|null, // The name of the cookie to use when using stateless protection. // Default: "csrf-token"
|
||||
* },
|
||||
* form?: bool|array{ // Form configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* csrf_protection?: array{
|
||||
* enabled?: scalar|null, // Default: null
|
||||
* token_id?: scalar|null, // Default: null
|
||||
* field_name?: scalar|null, // Default: "_token"
|
||||
* field_attr?: array<string, scalar|null>,
|
||||
* },
|
||||
* },
|
||||
* http_cache?: bool|array{ // HTTP cache configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* debug?: bool, // Default: "%kernel.debug%"
|
||||
* trace_level?: "none"|"short"|"full",
|
||||
* trace_header?: scalar|null,
|
||||
* default_ttl?: int,
|
||||
* private_headers?: list<scalar|null>,
|
||||
* skip_response_headers?: list<scalar|null>,
|
||||
* allow_reload?: bool,
|
||||
* allow_revalidate?: bool,
|
||||
* stale_while_revalidate?: int,
|
||||
* stale_if_error?: int,
|
||||
* terminate_on_cache_hit?: bool,
|
||||
* },
|
||||
* esi?: bool|array{ // ESI configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* ssi?: bool|array{ // SSI configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* fragments?: bool|array{ // Fragments configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* hinclude_default_template?: scalar|null, // Default: null
|
||||
* path?: scalar|null, // Default: "/_fragment"
|
||||
* },
|
||||
* profiler?: bool|array{ // Profiler configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* collect?: bool, // Default: true
|
||||
* collect_parameter?: scalar|null, // The name of the parameter to use to enable or disable collection on a per request basis. // Default: null
|
||||
* only_exceptions?: bool, // Default: false
|
||||
* only_main_requests?: bool, // Default: false
|
||||
* dsn?: scalar|null, // Default: "file:%kernel.cache_dir%/profiler"
|
||||
* collect_serializer_data?: bool, // Enables the serializer data collector and profiler panel. // Default: false
|
||||
* },
|
||||
* workflows?: bool|array{
|
||||
* enabled?: bool, // Default: false
|
||||
* workflows?: array<string, array{ // Default: []
|
||||
* audit_trail?: bool|array{
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* type?: "workflow"|"state_machine", // Default: "state_machine"
|
||||
* marking_store?: array{
|
||||
* type?: "method",
|
||||
* property?: scalar|null,
|
||||
* service?: scalar|null,
|
||||
* },
|
||||
* supports?: list<scalar|null>,
|
||||
* definition_validators?: list<scalar|null>,
|
||||
* support_strategy?: scalar|null,
|
||||
* initial_marking?: list<scalar|null>,
|
||||
* events_to_dispatch?: list<string>|null,
|
||||
* places?: list<array{ // Default: []
|
||||
* name: scalar|null,
|
||||
* metadata?: list<mixed>,
|
||||
* }>,
|
||||
* transitions: list<array{ // Default: []
|
||||
* name: string,
|
||||
* guard?: string, // An expression to block the transition.
|
||||
* from?: list<array{ // Default: []
|
||||
* place: string,
|
||||
* weight?: int, // Default: 1
|
||||
* }>,
|
||||
* to?: list<array{ // Default: []
|
||||
* place: string,
|
||||
* weight?: int, // Default: 1
|
||||
* }>,
|
||||
* weight?: int, // Default: 1
|
||||
* metadata?: list<mixed>,
|
||||
* }>,
|
||||
* metadata?: list<mixed>,
|
||||
* }>,
|
||||
* },
|
||||
* router?: bool|array{ // Router configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* resource: scalar|null,
|
||||
* type?: scalar|null,
|
||||
* cache_dir?: scalar|null, // Deprecated: Setting the "framework.router.cache_dir.cache_dir" configuration option is deprecated. It will be removed in version 8.0. // Default: "%kernel.build_dir%"
|
||||
* default_uri?: scalar|null, // The default URI used to generate URLs in a non-HTTP context. // Default: null
|
||||
* http_port?: scalar|null, // Default: 80
|
||||
* https_port?: scalar|null, // Default: 443
|
||||
* strict_requirements?: scalar|null, // set to true to throw an exception when a parameter does not match the requirements set to false to disable exceptions when a parameter does not match the requirements (and return null instead) set to null to disable parameter checks against requirements 'true' is the preferred configuration in development mode, while 'false' or 'null' might be preferred in production // Default: true
|
||||
* utf8?: bool, // Default: true
|
||||
* },
|
||||
* session?: bool|array{ // Session configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* storage_factory_id?: scalar|null, // Default: "session.storage.factory.native"
|
||||
* handler_id?: scalar|null, // Defaults to using the native session handler, or to the native *file* session handler if "save_path" is not null.
|
||||
* name?: scalar|null,
|
||||
* cookie_lifetime?: scalar|null,
|
||||
* cookie_path?: scalar|null,
|
||||
* cookie_domain?: scalar|null,
|
||||
* cookie_secure?: true|false|"auto", // Default: "auto"
|
||||
* cookie_httponly?: bool, // Default: true
|
||||
* cookie_samesite?: null|"lax"|"strict"|"none", // Default: "lax"
|
||||
* use_cookies?: bool,
|
||||
* gc_divisor?: scalar|null,
|
||||
* gc_probability?: scalar|null,
|
||||
* gc_maxlifetime?: scalar|null,
|
||||
* save_path?: scalar|null, // Defaults to "%kernel.cache_dir%/sessions" if the "handler_id" option is not null.
|
||||
* metadata_update_threshold?: int, // Seconds to wait between 2 session metadata updates. // Default: 0
|
||||
* sid_length?: int, // Deprecated: Setting the "framework.session.sid_length.sid_length" configuration option is deprecated. It will be removed in version 8.0. No alternative is provided as PHP 8.4 has deprecated the related option.
|
||||
* sid_bits_per_character?: int, // Deprecated: Setting the "framework.session.sid_bits_per_character.sid_bits_per_character" configuration option is deprecated. It will be removed in version 8.0. No alternative is provided as PHP 8.4 has deprecated the related option.
|
||||
* },
|
||||
* request?: bool|array{ // Request configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* formats?: array<string, string|list<scalar|null>>,
|
||||
* },
|
||||
* assets?: bool|array{ // Assets configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* strict_mode?: bool, // Throw an exception if an entry is missing from the manifest.json. // Default: false
|
||||
* version_strategy?: scalar|null, // Default: null
|
||||
* version?: scalar|null, // Default: null
|
||||
* version_format?: scalar|null, // Default: "%%s?%%s"
|
||||
* json_manifest_path?: scalar|null, // Default: null
|
||||
* base_path?: scalar|null, // Default: ""
|
||||
* base_urls?: list<scalar|null>,
|
||||
* packages?: array<string, array{ // Default: []
|
||||
* strict_mode?: bool, // Throw an exception if an entry is missing from the manifest.json. // Default: false
|
||||
* version_strategy?: scalar|null, // Default: null
|
||||
* version?: scalar|null,
|
||||
* version_format?: scalar|null, // Default: null
|
||||
* json_manifest_path?: scalar|null, // Default: null
|
||||
* base_path?: scalar|null, // Default: ""
|
||||
* base_urls?: list<scalar|null>,
|
||||
* }>,
|
||||
* },
|
||||
* asset_mapper?: bool|array{ // Asset Mapper configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* paths?: array<string, scalar|null>,
|
||||
* excluded_patterns?: list<scalar|null>,
|
||||
* exclude_dotfiles?: bool, // If true, any files starting with "." will be excluded from the asset mapper. // Default: true
|
||||
* server?: bool, // If true, a "dev server" will return the assets from the public directory (true in "debug" mode only by default). // Default: true
|
||||
* public_prefix?: scalar|null, // The public path where the assets will be written to (and served from when "server" is true). // Default: "/assets/"
|
||||
* missing_import_mode?: "strict"|"warn"|"ignore", // Behavior if an asset cannot be found when imported from JavaScript or CSS files - e.g. "import './non-existent.js'". "strict" means an exception is thrown, "warn" means a warning is logged, "ignore" means the import is left as-is. // Default: "warn"
|
||||
* extensions?: array<string, scalar|null>,
|
||||
* importmap_path?: scalar|null, // The path of the importmap.php file. // Default: "%kernel.project_dir%/importmap.php"
|
||||
* importmap_polyfill?: scalar|null, // The importmap name that will be used to load the polyfill. Set to false to disable. // Default: "es-module-shims"
|
||||
* importmap_script_attributes?: array<string, scalar|null>,
|
||||
* vendor_dir?: scalar|null, // The directory to store JavaScript vendors. // Default: "%kernel.project_dir%/assets/vendor"
|
||||
* precompress?: bool|array{ // Precompress assets with Brotli, Zstandard and gzip.
|
||||
* enabled?: bool, // Default: false
|
||||
* formats?: list<scalar|null>,
|
||||
* extensions?: list<scalar|null>,
|
||||
* },
|
||||
* },
|
||||
* translator?: bool|array{ // Translator configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* fallbacks?: list<scalar|null>,
|
||||
* logging?: bool, // Default: false
|
||||
* formatter?: scalar|null, // Default: "translator.formatter.default"
|
||||
* cache_dir?: scalar|null, // Default: "%kernel.cache_dir%/translations"
|
||||
* default_path?: scalar|null, // The default path used to load translations. // Default: "%kernel.project_dir%/translations"
|
||||
* paths?: list<scalar|null>,
|
||||
* pseudo_localization?: bool|array{
|
||||
* enabled?: bool, // Default: false
|
||||
* accents?: bool, // Default: true
|
||||
* expansion_factor?: float, // Default: 1.0
|
||||
* brackets?: bool, // Default: true
|
||||
* parse_html?: bool, // Default: false
|
||||
* localizable_html_attributes?: list<scalar|null>,
|
||||
* },
|
||||
* providers?: array<string, array{ // Default: []
|
||||
* dsn?: scalar|null,
|
||||
* domains?: list<scalar|null>,
|
||||
* locales?: list<scalar|null>,
|
||||
* }>,
|
||||
* globals?: array<string, string|array{ // Default: []
|
||||
* value?: mixed,
|
||||
* message?: string,
|
||||
* parameters?: array<string, scalar|null>,
|
||||
* domain?: string,
|
||||
* }>,
|
||||
* },
|
||||
* validation?: bool|array{ // Validation configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* cache?: scalar|null, // Deprecated: Setting the "framework.validation.cache.cache" configuration option is deprecated. It will be removed in version 8.0.
|
||||
* enable_attributes?: bool, // Default: true
|
||||
* static_method?: list<scalar|null>,
|
||||
* translation_domain?: scalar|null, // Default: "validators"
|
||||
* email_validation_mode?: "html5"|"html5-allow-no-tld"|"strict"|"loose", // Default: "html5"
|
||||
* mapping?: array{
|
||||
* paths?: list<scalar|null>,
|
||||
* },
|
||||
* not_compromised_password?: bool|array{
|
||||
* enabled?: bool, // When disabled, compromised passwords will be accepted as valid. // Default: true
|
||||
* endpoint?: scalar|null, // API endpoint for the NotCompromisedPassword Validator. // Default: null
|
||||
* },
|
||||
* disable_translation?: bool, // Default: false
|
||||
* auto_mapping?: array<string, array{ // Default: []
|
||||
* services?: list<scalar|null>,
|
||||
* }>,
|
||||
* },
|
||||
* annotations?: bool|array{
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* serializer?: bool|array{ // Serializer configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* enable_attributes?: bool, // Default: true
|
||||
* name_converter?: scalar|null,
|
||||
* circular_reference_handler?: scalar|null,
|
||||
* max_depth_handler?: scalar|null,
|
||||
* mapping?: array{
|
||||
* paths?: list<scalar|null>,
|
||||
* },
|
||||
* default_context?: list<mixed>,
|
||||
* named_serializers?: array<string, array{ // Default: []
|
||||
* name_converter?: scalar|null,
|
||||
* default_context?: list<mixed>,
|
||||
* include_built_in_normalizers?: bool, // Whether to include the built-in normalizers // Default: true
|
||||
* include_built_in_encoders?: bool, // Whether to include the built-in encoders // Default: true
|
||||
* }>,
|
||||
* },
|
||||
* property_access?: bool|array{ // Property access configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* magic_call?: bool, // Default: false
|
||||
* magic_get?: bool, // Default: true
|
||||
* magic_set?: bool, // Default: true
|
||||
* throw_exception_on_invalid_index?: bool, // Default: false
|
||||
* throw_exception_on_invalid_property_path?: bool, // Default: true
|
||||
* },
|
||||
* type_info?: bool|array{ // Type info configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* aliases?: array<string, scalar|null>,
|
||||
* },
|
||||
* property_info?: bool|array{ // Property info configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* with_constructor_extractor?: bool, // Registers the constructor extractor.
|
||||
* },
|
||||
* cache?: array{ // Cache configuration
|
||||
* prefix_seed?: scalar|null, // Used to namespace cache keys when using several apps with the same shared backend. // Default: "_%kernel.project_dir%.%kernel.container_class%"
|
||||
* app?: scalar|null, // App related cache pools configuration. // Default: "cache.adapter.filesystem"
|
||||
* system?: scalar|null, // System related cache pools configuration. // Default: "cache.adapter.system"
|
||||
* directory?: scalar|null, // Default: "%kernel.share_dir%/pools/app"
|
||||
* default_psr6_provider?: scalar|null,
|
||||
* default_redis_provider?: scalar|null, // Default: "redis://localhost"
|
||||
* default_valkey_provider?: scalar|null, // Default: "valkey://localhost"
|
||||
* default_memcached_provider?: scalar|null, // Default: "memcached://localhost"
|
||||
* default_doctrine_dbal_provider?: scalar|null, // Default: "database_connection"
|
||||
* default_pdo_provider?: scalar|null, // Default: null
|
||||
* pools?: array<string, array{ // Default: []
|
||||
* adapters?: list<scalar|null>,
|
||||
* tags?: scalar|null, // Default: null
|
||||
* public?: bool, // Default: false
|
||||
* default_lifetime?: scalar|null, // Default lifetime of the pool.
|
||||
* provider?: scalar|null, // Overwrite the setting from the default provider for this adapter.
|
||||
* early_expiration_message_bus?: scalar|null,
|
||||
* clearer?: scalar|null,
|
||||
* }>,
|
||||
* },
|
||||
* php_errors?: array{ // PHP errors handling configuration
|
||||
* log?: mixed, // Use the application logger instead of the PHP logger for logging PHP errors. // Default: true
|
||||
* throw?: bool, // Throw PHP errors as \ErrorException instances. // Default: true
|
||||
* },
|
||||
* exceptions?: array<string, array{ // Default: []
|
||||
* log_level?: scalar|null, // The level of log message. Null to let Symfony decide. // Default: null
|
||||
* status_code?: scalar|null, // The status code of the response. Null or 0 to let Symfony decide. // Default: null
|
||||
* log_channel?: scalar|null, // The channel of log message. Null to let Symfony decide. // Default: null
|
||||
* }>,
|
||||
* web_link?: bool|array{ // Web links configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* lock?: bool|string|array{ // Lock configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* resources?: array<string, string|list<scalar|null>>,
|
||||
* },
|
||||
* semaphore?: bool|string|array{ // Semaphore configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* resources?: array<string, scalar|null>,
|
||||
* },
|
||||
* messenger?: bool|array{ // Messenger configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* routing?: array<string, array{ // Default: []
|
||||
* senders?: list<scalar|null>,
|
||||
* }>,
|
||||
* serializer?: array{
|
||||
* default_serializer?: scalar|null, // Service id to use as the default serializer for the transports. // Default: "messenger.transport.native_php_serializer"
|
||||
* symfony_serializer?: array{
|
||||
* format?: scalar|null, // Serialization format for the messenger.transport.symfony_serializer service (which is not the serializer used by default). // Default: "json"
|
||||
* context?: array<string, mixed>,
|
||||
* },
|
||||
* },
|
||||
* transports?: array<string, string|array{ // Default: []
|
||||
* dsn?: scalar|null,
|
||||
* serializer?: scalar|null, // Service id of a custom serializer to use. // Default: null
|
||||
* options?: list<mixed>,
|
||||
* failure_transport?: scalar|null, // Transport name to send failed messages to (after all retries have failed). // Default: null
|
||||
* retry_strategy?: string|array{
|
||||
* service?: scalar|null, // Service id to override the retry strategy entirely. // Default: null
|
||||
* max_retries?: int, // Default: 3
|
||||
* delay?: int, // Time in ms to delay (or the initial value when multiplier is used). // Default: 1000
|
||||
* multiplier?: float, // If greater than 1, delay will grow exponentially for each retry: this delay = (delay * (multiple ^ retries)). // Default: 2
|
||||
* max_delay?: int, // Max time in ms that a retry should ever be delayed (0 = infinite). // Default: 0
|
||||
* jitter?: float, // Randomness to apply to the delay (between 0 and 1). // Default: 0.1
|
||||
* },
|
||||
* rate_limiter?: scalar|null, // Rate limiter name to use when processing messages. // Default: null
|
||||
* }>,
|
||||
* failure_transport?: scalar|null, // Transport name to send failed messages to (after all retries have failed). // Default: null
|
||||
* stop_worker_on_signals?: list<scalar|null>,
|
||||
* default_bus?: scalar|null, // Default: null
|
||||
* buses?: array<string, array{ // Default: {"messenger.bus.default":{"default_middleware":{"enabled":true,"allow_no_handlers":false,"allow_no_senders":true},"middleware":[]}}
|
||||
* default_middleware?: bool|string|array{
|
||||
* enabled?: bool, // Default: true
|
||||
* allow_no_handlers?: bool, // Default: false
|
||||
* allow_no_senders?: bool, // Default: true
|
||||
* },
|
||||
* middleware?: list<string|array{ // Default: []
|
||||
* id: scalar|null,
|
||||
* arguments?: list<mixed>,
|
||||
* }>,
|
||||
* }>,
|
||||
* },
|
||||
* scheduler?: bool|array{ // Scheduler configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* disallow_search_engine_index?: bool, // Enabled by default when debug is enabled. // Default: true
|
||||
* http_client?: bool|array{ // HTTP Client configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* max_host_connections?: int, // The maximum number of connections to a single host.
|
||||
* default_options?: array{
|
||||
* headers?: array<string, mixed>,
|
||||
* vars?: array<string, mixed>,
|
||||
* max_redirects?: int, // The maximum number of redirects to follow.
|
||||
* http_version?: scalar|null, // The default HTTP version, typically 1.1 or 2.0, leave to null for the best version.
|
||||
* resolve?: array<string, scalar|null>,
|
||||
* proxy?: scalar|null, // The URL of the proxy to pass requests through or null for automatic detection.
|
||||
* no_proxy?: scalar|null, // A comma separated list of hosts that do not require a proxy to be reached.
|
||||
* timeout?: float, // The idle timeout, defaults to the "default_socket_timeout" ini parameter.
|
||||
* max_duration?: float, // The maximum execution time for the request+response as a whole.
|
||||
* bindto?: scalar|null, // A network interface name, IP address, a host name or a UNIX socket to bind to.
|
||||
* verify_peer?: bool, // Indicates if the peer should be verified in a TLS context.
|
||||
* verify_host?: bool, // Indicates if the host should exist as a certificate common name.
|
||||
* cafile?: scalar|null, // A certificate authority file.
|
||||
* capath?: scalar|null, // A directory that contains multiple certificate authority files.
|
||||
* local_cert?: scalar|null, // A PEM formatted certificate file.
|
||||
* local_pk?: scalar|null, // A private key file.
|
||||
* passphrase?: scalar|null, // The passphrase used to encrypt the "local_pk" file.
|
||||
* ciphers?: scalar|null, // A list of TLS ciphers separated by colons, commas or spaces (e.g. "RC3-SHA:TLS13-AES-128-GCM-SHA256"...)
|
||||
* peer_fingerprint?: array{ // Associative array: hashing algorithm => hash(es).
|
||||
* sha1?: mixed,
|
||||
* pin-sha256?: mixed,
|
||||
* md5?: mixed,
|
||||
* },
|
||||
* crypto_method?: scalar|null, // The minimum version of TLS to accept; must be one of STREAM_CRYPTO_METHOD_TLSv*_CLIENT constants.
|
||||
* extra?: array<string, mixed>,
|
||||
* rate_limiter?: scalar|null, // Rate limiter name to use for throttling requests. // Default: null
|
||||
* caching?: bool|array{ // Caching configuration.
|
||||
* enabled?: bool, // Default: false
|
||||
* cache_pool?: string, // The taggable cache pool to use for storing the responses. // Default: "cache.http_client"
|
||||
* shared?: bool, // Indicates whether the cache is shared (public) or private. // Default: true
|
||||
* max_ttl?: int, // The maximum TTL (in seconds) allowed for cached responses. Null means no cap. // Default: null
|
||||
* },
|
||||
* retry_failed?: bool|array{
|
||||
* enabled?: bool, // Default: false
|
||||
* retry_strategy?: scalar|null, // service id to override the retry strategy. // Default: null
|
||||
* http_codes?: array<string, array{ // Default: []
|
||||
* code?: int,
|
||||
* methods?: list<string>,
|
||||
* }>,
|
||||
* max_retries?: int, // Default: 3
|
||||
* delay?: int, // Time in ms to delay (or the initial value when multiplier is used). // Default: 1000
|
||||
* multiplier?: float, // If greater than 1, delay will grow exponentially for each retry: delay * (multiple ^ retries). // Default: 2
|
||||
* max_delay?: int, // Max time in ms that a retry should ever be delayed (0 = infinite). // Default: 0
|
||||
* jitter?: float, // Randomness in percent (between 0 and 1) to apply to the delay. // Default: 0.1
|
||||
* },
|
||||
* },
|
||||
* mock_response_factory?: scalar|null, // The id of the service that should generate mock responses. It should be either an invokable or an iterable.
|
||||
* scoped_clients?: array<string, string|array{ // Default: []
|
||||
* scope?: scalar|null, // The regular expression that the request URL must match before adding the other options. When none is provided, the base URI is used instead.
|
||||
* base_uri?: scalar|null, // The URI to resolve relative URLs, following rules in RFC 3985, section 2.
|
||||
* auth_basic?: scalar|null, // An HTTP Basic authentication "username:password".
|
||||
* auth_bearer?: scalar|null, // A token enabling HTTP Bearer authorization.
|
||||
* auth_ntlm?: scalar|null, // A "username:password" pair to use Microsoft NTLM authentication (requires the cURL extension).
|
||||
* query?: array<string, scalar|null>,
|
||||
* headers?: array<string, mixed>,
|
||||
* max_redirects?: int, // The maximum number of redirects to follow.
|
||||
* http_version?: scalar|null, // The default HTTP version, typically 1.1 or 2.0, leave to null for the best version.
|
||||
* resolve?: array<string, scalar|null>,
|
||||
* proxy?: scalar|null, // The URL of the proxy to pass requests through or null for automatic detection.
|
||||
* no_proxy?: scalar|null, // A comma separated list of hosts that do not require a proxy to be reached.
|
||||
* timeout?: float, // The idle timeout, defaults to the "default_socket_timeout" ini parameter.
|
||||
* max_duration?: float, // The maximum execution time for the request+response as a whole.
|
||||
* bindto?: scalar|null, // A network interface name, IP address, a host name or a UNIX socket to bind to.
|
||||
* verify_peer?: bool, // Indicates if the peer should be verified in a TLS context.
|
||||
* verify_host?: bool, // Indicates if the host should exist as a certificate common name.
|
||||
* cafile?: scalar|null, // A certificate authority file.
|
||||
* capath?: scalar|null, // A directory that contains multiple certificate authority files.
|
||||
* local_cert?: scalar|null, // A PEM formatted certificate file.
|
||||
* local_pk?: scalar|null, // A private key file.
|
||||
* passphrase?: scalar|null, // The passphrase used to encrypt the "local_pk" file.
|
||||
* ciphers?: scalar|null, // A list of TLS ciphers separated by colons, commas or spaces (e.g. "RC3-SHA:TLS13-AES-128-GCM-SHA256"...).
|
||||
* peer_fingerprint?: array{ // Associative array: hashing algorithm => hash(es).
|
||||
* sha1?: mixed,
|
||||
* pin-sha256?: mixed,
|
||||
* md5?: mixed,
|
||||
* },
|
||||
* crypto_method?: scalar|null, // The minimum version of TLS to accept; must be one of STREAM_CRYPTO_METHOD_TLSv*_CLIENT constants.
|
||||
* extra?: array<string, mixed>,
|
||||
* rate_limiter?: scalar|null, // Rate limiter name to use for throttling requests. // Default: null
|
||||
* caching?: bool|array{ // Caching configuration.
|
||||
* enabled?: bool, // Default: false
|
||||
* cache_pool?: string, // The taggable cache pool to use for storing the responses. // Default: "cache.http_client"
|
||||
* shared?: bool, // Indicates whether the cache is shared (public) or private. // Default: true
|
||||
* max_ttl?: int, // The maximum TTL (in seconds) allowed for cached responses. Null means no cap. // Default: null
|
||||
* },
|
||||
* retry_failed?: bool|array{
|
||||
* enabled?: bool, // Default: false
|
||||
* retry_strategy?: scalar|null, // service id to override the retry strategy. // Default: null
|
||||
* http_codes?: array<string, array{ // Default: []
|
||||
* code?: int,
|
||||
* methods?: list<string>,
|
||||
* }>,
|
||||
* max_retries?: int, // Default: 3
|
||||
* delay?: int, // Time in ms to delay (or the initial value when multiplier is used). // Default: 1000
|
||||
* multiplier?: float, // If greater than 1, delay will grow exponentially for each retry: delay * (multiple ^ retries). // Default: 2
|
||||
* max_delay?: int, // Max time in ms that a retry should ever be delayed (0 = infinite). // Default: 0
|
||||
* jitter?: float, // Randomness in percent (between 0 and 1) to apply to the delay. // Default: 0.1
|
||||
* },
|
||||
* }>,
|
||||
* },
|
||||
* mailer?: bool|array{ // Mailer configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* message_bus?: scalar|null, // The message bus to use. Defaults to the default bus if the Messenger component is installed. // Default: null
|
||||
* dsn?: scalar|null, // Default: null
|
||||
* transports?: array<string, scalar|null>,
|
||||
* envelope?: array{ // Mailer Envelope configuration
|
||||
* sender?: scalar|null,
|
||||
* recipients?: list<scalar|null>,
|
||||
* allowed_recipients?: list<scalar|null>,
|
||||
* },
|
||||
* headers?: array<string, string|array{ // Default: []
|
||||
* value?: mixed,
|
||||
* }>,
|
||||
* dkim_signer?: bool|array{ // DKIM signer configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* key?: scalar|null, // Key content, or path to key (in PEM format with the `file://` prefix) // Default: ""
|
||||
* domain?: scalar|null, // Default: ""
|
||||
* select?: scalar|null, // Default: ""
|
||||
* passphrase?: scalar|null, // The private key passphrase // Default: ""
|
||||
* options?: array<string, mixed>,
|
||||
* },
|
||||
* smime_signer?: bool|array{ // S/MIME signer configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* key?: scalar|null, // Path to key (in PEM format) // Default: ""
|
||||
* certificate?: scalar|null, // Path to certificate (in PEM format without the `file://` prefix) // Default: ""
|
||||
* passphrase?: scalar|null, // The private key passphrase // Default: null
|
||||
* extra_certificates?: scalar|null, // Default: null
|
||||
* sign_options?: int, // Default: null
|
||||
* },
|
||||
* smime_encrypter?: bool|array{ // S/MIME encrypter configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* repository?: scalar|null, // S/MIME certificate repository service. This service shall implement the `Symfony\Component\Mailer\EventListener\SmimeCertificateRepositoryInterface`. // Default: ""
|
||||
* cipher?: int, // A set of algorithms used to encrypt the message // Default: null
|
||||
* },
|
||||
* },
|
||||
* secrets?: bool|array{
|
||||
* enabled?: bool, // Default: true
|
||||
* vault_directory?: scalar|null, // Default: "%kernel.project_dir%/config/secrets/%kernel.runtime_environment%"
|
||||
* local_dotenv_file?: scalar|null, // Default: "%kernel.project_dir%/.env.%kernel.runtime_environment%.local"
|
||||
* decryption_env_var?: scalar|null, // Default: "base64:default::SYMFONY_DECRYPTION_SECRET"
|
||||
* },
|
||||
* notifier?: bool|array{ // Notifier configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* message_bus?: scalar|null, // The message bus to use. Defaults to the default bus if the Messenger component is installed. // Default: null
|
||||
* chatter_transports?: array<string, scalar|null>,
|
||||
* texter_transports?: array<string, scalar|null>,
|
||||
* notification_on_failed_messages?: bool, // Default: false
|
||||
* channel_policy?: array<string, string|list<scalar|null>>,
|
||||
* admin_recipients?: list<array{ // Default: []
|
||||
* email?: scalar|null,
|
||||
* phone?: scalar|null, // Default: ""
|
||||
* }>,
|
||||
* },
|
||||
* rate_limiter?: bool|array{ // Rate limiter configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* limiters?: array<string, array{ // Default: []
|
||||
* lock_factory?: scalar|null, // The service ID of the lock factory used by this limiter (or null to disable locking). // Default: "auto"
|
||||
* cache_pool?: scalar|null, // The cache pool to use for storing the current limiter state. // Default: "cache.rate_limiter"
|
||||
* storage_service?: scalar|null, // The service ID of a custom storage implementation, this precedes any configured "cache_pool". // Default: null
|
||||
* policy: "fixed_window"|"token_bucket"|"sliding_window"|"compound"|"no_limit", // The algorithm to be used by this limiter.
|
||||
* limiters?: list<scalar|null>,
|
||||
* limit?: int, // The maximum allowed hits in a fixed interval or burst.
|
||||
* interval?: scalar|null, // Configures the fixed interval if "policy" is set to "fixed_window" or "sliding_window". The value must be a number followed by "second", "minute", "hour", "day", "week" or "month" (or their plural equivalent).
|
||||
* rate?: array{ // Configures the fill rate if "policy" is set to "token_bucket".
|
||||
* interval?: scalar|null, // Configures the rate interval. The value must be a number followed by "second", "minute", "hour", "day", "week" or "month" (or their plural equivalent).
|
||||
* amount?: int, // Amount of tokens to add each interval. // Default: 1
|
||||
* },
|
||||
* }>,
|
||||
* },
|
||||
* uid?: bool|array{ // Uid configuration
|
||||
* enabled?: bool, // Default: true
|
||||
* default_uuid_version?: 7|6|4|1, // Default: 7
|
||||
* name_based_uuid_version?: 5|3, // Default: 5
|
||||
* name_based_uuid_namespace?: scalar|null,
|
||||
* time_based_uuid_version?: 7|6|1, // Default: 7
|
||||
* time_based_uuid_node?: scalar|null,
|
||||
* },
|
||||
* html_sanitizer?: bool|array{ // HtmlSanitizer configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* sanitizers?: array<string, array{ // Default: []
|
||||
* allow_safe_elements?: bool, // Allows "safe" elements and attributes. // Default: false
|
||||
* allow_static_elements?: bool, // Allows all static elements and attributes from the W3C Sanitizer API standard. // Default: false
|
||||
* allow_elements?: array<string, mixed>,
|
||||
* block_elements?: list<string>,
|
||||
* drop_elements?: list<string>,
|
||||
* allow_attributes?: array<string, mixed>,
|
||||
* drop_attributes?: array<string, mixed>,
|
||||
* force_attributes?: array<string, array<string, string>>,
|
||||
* force_https_urls?: bool, // Transforms URLs using the HTTP scheme to use the HTTPS scheme instead. // Default: false
|
||||
* allowed_link_schemes?: list<string>,
|
||||
* allowed_link_hosts?: list<string>|null,
|
||||
* allow_relative_links?: bool, // Allows relative URLs to be used in links href attributes. // Default: false
|
||||
* allowed_media_schemes?: list<string>,
|
||||
* allowed_media_hosts?: list<string>|null,
|
||||
* allow_relative_medias?: bool, // Allows relative URLs to be used in media source attributes (img, audio, video, ...). // Default: false
|
||||
* with_attribute_sanitizers?: list<string>,
|
||||
* without_attribute_sanitizers?: list<string>,
|
||||
* max_input_length?: int, // The maximum length allowed for the sanitized input. // Default: 0
|
||||
* }>,
|
||||
* },
|
||||
* webhook?: bool|array{ // Webhook configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* message_bus?: scalar|null, // The message bus to use. // Default: "messenger.default_bus"
|
||||
* routing?: array<string, array{ // Default: []
|
||||
* service: scalar|null,
|
||||
* secret?: scalar|null, // Default: ""
|
||||
* }>,
|
||||
* },
|
||||
* remote-event?: bool|array{ // RemoteEvent configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* json_streamer?: bool|array{ // JSON streamer configuration
|
||||
* enabled?: bool, // Default: false
|
||||
* },
|
||||
* }
|
||||
* @psalm-type TwigConfig = array{
|
||||
* form_themes?: list<scalar|null>,
|
||||
* globals?: array<string, array{ // Default: []
|
||||
* id?: scalar|null,
|
||||
* type?: scalar|null,
|
||||
* value?: mixed,
|
||||
* }>,
|
||||
* autoescape_service?: scalar|null, // Default: null
|
||||
* autoescape_service_method?: scalar|null, // Default: null
|
||||
* base_template_class?: scalar|null, // Deprecated: The child node "base_template_class" at path "twig.base_template_class" is deprecated.
|
||||
* cache?: scalar|null, // Default: true
|
||||
* charset?: scalar|null, // Default: "%kernel.charset%"
|
||||
* debug?: bool, // Default: "%kernel.debug%"
|
||||
* strict_variables?: bool, // Default: "%kernel.debug%"
|
||||
* auto_reload?: scalar|null,
|
||||
* optimizations?: int,
|
||||
* default_path?: scalar|null, // The default path used to load templates. // Default: "%kernel.project_dir%/templates"
|
||||
* file_name_pattern?: list<scalar|null>,
|
||||
* paths?: array<string, mixed>,
|
||||
* date?: array{ // The default format options used by the date filter.
|
||||
* format?: scalar|null, // Default: "F j, Y H:i"
|
||||
* interval_format?: scalar|null, // Default: "%d days"
|
||||
* timezone?: scalar|null, // The timezone used when formatting dates, when set to null, the timezone returned by date_default_timezone_get() is used. // Default: null
|
||||
* },
|
||||
* number_format?: array{ // The default format options for the number_format filter.
|
||||
* decimals?: int, // Default: 0
|
||||
* decimal_point?: scalar|null, // Default: "."
|
||||
* thousands_separator?: scalar|null, // Default: ","
|
||||
* },
|
||||
* mailer?: array{
|
||||
* html_to_text_converter?: scalar|null, // A service implementing the "Symfony\Component\Mime\HtmlToTextConverter\HtmlToTextConverterInterface". // Default: null
|
||||
* },
|
||||
* }
|
||||
* @psalm-type ConfigType = array{
|
||||
* imports?: ImportsConfig,
|
||||
* parameters?: ParametersConfig,
|
||||
* services?: ServicesConfig,
|
||||
* framework?: FrameworkConfig,
|
||||
* twig?: TwigConfig,
|
||||
* "when@dev"?: array{
|
||||
* imports?: ImportsConfig,
|
||||
* parameters?: ParametersConfig,
|
||||
* services?: ServicesConfig,
|
||||
* framework?: FrameworkConfig,
|
||||
* twig?: TwigConfig,
|
||||
* },
|
||||
* "when@prod"?: array{
|
||||
* imports?: ImportsConfig,
|
||||
* parameters?: ParametersConfig,
|
||||
* services?: ServicesConfig,
|
||||
* framework?: FrameworkConfig,
|
||||
* twig?: TwigConfig,
|
||||
* },
|
||||
* "when@test"?: array{
|
||||
* imports?: ImportsConfig,
|
||||
* parameters?: ParametersConfig,
|
||||
* services?: ServicesConfig,
|
||||
* framework?: FrameworkConfig,
|
||||
* twig?: TwigConfig,
|
||||
* },
|
||||
* ...<string, ExtensionType|array{ // extra keys must follow the when@%env% pattern or match an extension alias
|
||||
* imports?: ImportsConfig,
|
||||
* parameters?: ParametersConfig,
|
||||
* services?: ServicesConfig,
|
||||
* ...<string, ExtensionType>,
|
||||
* }>
|
||||
* }
|
||||
*/
|
||||
final class App
|
||||
{
|
||||
/**
|
||||
* @param ConfigType $config
|
||||
*
|
||||
* @psalm-return ConfigType
|
||||
*/
|
||||
public static function config(array $config): array
|
||||
{
|
||||
return AppReference::config($config);
|
||||
}
|
||||
}
|
||||
|
||||
namespace Symfony\Component\Routing\Loader\Configurator;
|
||||
|
||||
/**
|
||||
* This class provides array-shapes for configuring the routes of an application.
|
||||
*
|
||||
* Example:
|
||||
*
|
||||
* ```php
|
||||
* // config/routes.php
|
||||
* namespace Symfony\Component\Routing\Loader\Configurator;
|
||||
*
|
||||
* return Routes::config([
|
||||
* 'controllers' => [
|
||||
* 'resource' => 'routing.controllers',
|
||||
* ],
|
||||
* ]);
|
||||
* ```
|
||||
*
|
||||
* @psalm-type RouteConfig = array{
|
||||
* path: string|array<string,string>,
|
||||
* controller?: string,
|
||||
* methods?: string|list<string>,
|
||||
* requirements?: array<string,string>,
|
||||
* defaults?: array<string,mixed>,
|
||||
* options?: array<string,mixed>,
|
||||
* host?: string|array<string,string>,
|
||||
* schemes?: string|list<string>,
|
||||
* condition?: string,
|
||||
* locale?: string,
|
||||
* format?: string,
|
||||
* utf8?: bool,
|
||||
* stateless?: bool,
|
||||
* }
|
||||
* @psalm-type ImportConfig = array{
|
||||
* resource: string,
|
||||
* type?: string,
|
||||
* exclude?: string|list<string>,
|
||||
* prefix?: string|array<string,string>,
|
||||
* name_prefix?: string,
|
||||
* trailing_slash_on_root?: bool,
|
||||
* controller?: string,
|
||||
* methods?: string|list<string>,
|
||||
* requirements?: array<string,string>,
|
||||
* defaults?: array<string,mixed>,
|
||||
* options?: array<string,mixed>,
|
||||
* host?: string|array<string,string>,
|
||||
* schemes?: string|list<string>,
|
||||
* condition?: string,
|
||||
* locale?: string,
|
||||
* format?: string,
|
||||
* utf8?: bool,
|
||||
* stateless?: bool,
|
||||
* }
|
||||
* @psalm-type AliasConfig = array{
|
||||
* alias: string,
|
||||
* deprecated?: array{package:string, version:string, message?:string},
|
||||
* }
|
||||
* @psalm-type RoutesConfig = array{
|
||||
* "when@dev"?: array<string, RouteConfig|ImportConfig|AliasConfig>,
|
||||
* "when@prod"?: array<string, RouteConfig|ImportConfig|AliasConfig>,
|
||||
* "when@test"?: array<string, RouteConfig|ImportConfig|AliasConfig>,
|
||||
* ...<string, RouteConfig|ImportConfig|AliasConfig>
|
||||
* }
|
||||
*/
|
||||
final class Routes
|
||||
{
|
||||
/**
|
||||
* @param RoutesConfig $config
|
||||
*
|
||||
* @psalm-return RoutesConfig
|
||||
*/
|
||||
public static function config(array $config): array
|
||||
{
|
||||
return $config;
|
||||
}
|
||||
}
|
||||
@@ -1,11 +0,0 @@
|
||||
# yaml-language-server: $schema=../vendor/symfony/routing/Loader/schema/routing.schema.json
|
||||
|
||||
# This file is the entry point to configure the routes of your app.
|
||||
# Methods with the #[Route] attribute are automatically imported.
|
||||
# See also https://symfony.com/doc/current/routing.html
|
||||
|
||||
# To list all registered routes, run the following command:
|
||||
# bin/console debug:router
|
||||
|
||||
controllers:
|
||||
resource: routing.controllers
|
||||
@@ -1,4 +0,0 @@
|
||||
when@dev:
|
||||
_errors:
|
||||
resource: '@FrameworkBundle/Resources/config/routing/errors.php'
|
||||
prefix: /_error
|
||||
+25
-27
@@ -8,42 +8,40 @@
|
||||
# https://symfony.com/doc/current/best_practices.html
|
||||
# #use-parameters-for-application-configuration
|
||||
parameters:
|
||||
# --- main variables ---
|
||||
# --- main options ---
|
||||
# URI containing secret and config for TOTP, which determines the token to login
|
||||
# app will generate one, if not provided, but you should copy it to your .env file
|
||||
# format: "otpauth://totp/<label>?secret=<secret-key>"
|
||||
env(TOTP_URI): '' # blank to have the app generate one at random
|
||||
# how long will someone stay logged in, measured in seconds, zero for DEFAULT
|
||||
env(COOKIE_TTL): '2592000' # default 30 days
|
||||
# rate limiting can *NOT* be disabled, but you could allow hundreds of logins a second
|
||||
# number of consecutive failed login attempts before we block the ip address
|
||||
env(LIMIT): '4' # default 4 failed login attempts before blocking
|
||||
# time between failed login attempts that are consecutive, in seconds, zero for DEFAULT
|
||||
env(LIMIT_TIMEOUT): '21600' # default 6 hours
|
||||
# how long a blocked ip address stay blocks, in seconds, zero for DEFAULT
|
||||
env(LIMIT_TTL): '86400' # default 24 hours
|
||||
# Enable optional redirection to a dedicated authentication subdomain
|
||||
env(SUBDOMAIN_REDIRECT): '0' # boolean, 1 to enable
|
||||
# The subdomain (e.g., auth.example.com) to which unauthenticated users are redirected
|
||||
env(AUTH_SUBDOMAIN): ''
|
||||
|
||||
# --- extra variables ---
|
||||
# query parameter prefix to prevent collisions
|
||||
env(QUERY_PREFIX): '_preauth_'
|
||||
# --- extra options ---
|
||||
# how long do we allow all traffic from an ip address after successful login
|
||||
# could be useful if you have a system which does not handle cookies
|
||||
env(IP_TTL): '0' # default disabled, time in seconds
|
||||
# if desired, in addition to supporting a TOTP, you can set a static password
|
||||
# TODO rely on checking enabled, instead of the secret directly throughout the code
|
||||
env(STATIC_SECRET_ENABLED): '0' # boolean
|
||||
env(STATIC_SECRET): '' # default disabled
|
||||
# once blocked, do we respond with "I'm a teapot", false to use "Too many requests"
|
||||
env(TEAPOT): '1' # boolean
|
||||
|
||||
# --- styling variables ---
|
||||
# --- rate limiting ---
|
||||
# Note: rate limiting can *NOT* be disabled, but you could allow hundreds of logins a second
|
||||
# rate limiting, default is the lower of 2 per 30 seconds or 10 per hour
|
||||
env(BURST_COUNT): 2 # 2 per 30 seconds
|
||||
env(BURST_TIME): 30 # seconds
|
||||
env(UPPER_COUNT): 10 # 10 per hour
|
||||
env(UPPER_TIME): 3600 # seconds (1 hour)
|
||||
|
||||
# --- styling options ---
|
||||
env(TITLE): 'Pre-Authentication System'
|
||||
env(BG_COLOR): '#029386'
|
||||
env(FG_COLOR): '#ffffff'
|
||||
env(ERROR_COLOR): '#ffb16d'
|
||||
env(BG_COLOR): '#029386' # teal
|
||||
env(FG_COLOR): '#ffffff' # white
|
||||
env(ERROR_COLOR): '#ffb16d' # apricot (light orange)
|
||||
env(ID_NAME): 'Session ID'
|
||||
env(TOKEN_NAME): 'Authentication Token'
|
||||
env(PASSWORD_NAME): 'Authentication Password'
|
||||
env(SUBMIT_NAME): 'Submit'
|
||||
env(ERROR_MESSAGE): 'Unsuccessful login attempt'
|
||||
# title and message to use on block page, if teapot is true
|
||||
@@ -53,16 +51,16 @@ parameters:
|
||||
env(TOO_MANY_TITLE): 'Too many requests'
|
||||
env(TOO_MANY_MESSAGE): 'Try again later'
|
||||
|
||||
app.cookie_ttl: '%env(COOKIE_TTL)%'
|
||||
app.limit: '%env(LIMIT)%'
|
||||
app.limit_timeout: '%env(LIMIT_TIMEOUT)%'
|
||||
app.limit_ttl: '%env(LIMIT_TTL)%'
|
||||
app.query_prefix: '%env(QUERY_PREFIX)%'
|
||||
# --- debug options ---
|
||||
env(SHELL_VERBOSITY): '0' # set to 3 to log debug
|
||||
|
||||
# --- application variables ---
|
||||
app.totp_uri: '%env(TOTP_URI)%'
|
||||
app.cookie_ttl: '%env(COOKIE_TTL)%'
|
||||
app.subdomain_redirect: '%env(SUBDOMAIN_REDIRECT)%'
|
||||
app.auth_subdomain: '%env(AUTH_SUBDOMAIN)%'
|
||||
|
||||
app.ip_ttl: '%env(IP_TTL)%'
|
||||
app.static_secret_enabled: '%env(STATIC_SECRET_ENABLED)%'
|
||||
app.static_secret: '%env(STATIC_SECRET)%'
|
||||
app.teapot: '%env(TEAPOT)%'
|
||||
|
||||
app.error_message: '%env(ERROR_MESSAGE)%'
|
||||
|
||||
+20
-25
@@ -1,33 +1,28 @@
|
||||
# if using caddy v2.9.x+ you can use this snippet
|
||||
# snippet to put the preauth system in front any service easily
|
||||
(preauth) {
|
||||
# make sure caddy and preauth are on the same network
|
||||
reverse_proxy {args[0]} preauth {
|
||||
# leave body content for protected service
|
||||
method GET
|
||||
# if auth is successful, send request to protected service
|
||||
@preauth_ok status 2xx
|
||||
handle_response @preauth_ok {
|
||||
{block}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# example of securing full subdomain
|
||||
# TODO replace domain and service name
|
||||
# example of securing full service
|
||||
# TODO replace domain and service name and port
|
||||
service.example.com {
|
||||
import preauth * {
|
||||
reverse_proxy service_container
|
||||
forward_auth preauth {
|
||||
uri {uri}
|
||||
copy_headers Remote-User
|
||||
}
|
||||
reverse_proxy service-container:80
|
||||
}
|
||||
|
||||
# you can only lock down only select paths
|
||||
# or any other match criteria, if desired
|
||||
# https://protected.example.com/secure/
|
||||
# you can choose to only restrict select paths
|
||||
# or any other Caddy match criteria, if desired
|
||||
# IE: https://protected.example.com/secure/
|
||||
protected.example.com {
|
||||
import preauth /secure/* {
|
||||
reverse_proxy protected-service:9000
|
||||
# note any request that does not start with "/secure/" is NOT protected
|
||||
forward_auth /secure/* preauth {
|
||||
uri {uri}
|
||||
copy_headers Remote-User
|
||||
}
|
||||
reverse_proxy exposed-service:9000
|
||||
reverse_proxy protected-service:9000
|
||||
}
|
||||
|
||||
# optionally, if you want to use a subdomain for centeral preauth
|
||||
# set SUBDOMAIN_REDIRECT to true
|
||||
# and AUTH_SUBDOMAIN to match the subdomain you use here
|
||||
auth.example.com {
|
||||
reverse_proxy preauth
|
||||
}
|
||||
|
||||
+2
-5
@@ -1,7 +1,7 @@
|
||||
services:
|
||||
preauth:
|
||||
env_file:
|
||||
# TODO rename "env.example" to ".env", edit as needed
|
||||
# TODO rename "example.env" to ".env", edit as needed
|
||||
# strongly recommend setting TOTP_URI, if not provided the app
|
||||
# will generate one for you, please copy it into your .env file
|
||||
- .env
|
||||
@@ -10,10 +10,7 @@ services:
|
||||
image: digitaladapt/preauth:latest
|
||||
restart: unless-stopped
|
||||
# if you wish to set the user, you must make sure that the user
|
||||
# can write to /app/var/ within the container, and that all files
|
||||
# and folders within are writable as well
|
||||
# IE: `$chown -R <uid>:<gid> /path/to/volume/of/app/var`
|
||||
#
|
||||
# can write to /config and /data within the container
|
||||
#user: <uid>:<gid>
|
||||
volumes:
|
||||
- preauth-config:/config
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# --- Main Options ---
|
||||
# --- main options ---
|
||||
|
||||
# URI containing secret and config for TOTP, which determines the token to login
|
||||
# app will generate one, if not provided, but you should copy it to your .env file
|
||||
@@ -8,32 +8,33 @@
|
||||
# how long will someone stay logged in, measured in seconds, zero for DEFAULT
|
||||
#COOKIE_TTL=2592000 # default 30 days
|
||||
|
||||
# NOTE: rate limiting can *NOT* be disabled,
|
||||
# but you could allow hundreds of logins a second
|
||||
# we can use a central auth, so that users only need to login once to have access to
|
||||
# multiple services. Requires using sub-domains under the same domain.
|
||||
# IE: if enabled have "service-one.example.com" redirect "auth.example.com", and after
|
||||
# successful auth, user can visit "service-two.example.com" without having to login again.
|
||||
#SUBDOMAIN_REDIRECT=false # default disabled, boolean
|
||||
#AUTH_SUBDOMAIN='' # blank, hostname we send user to, to see login page
|
||||
|
||||
# number of consecutive failed login attempts before we block the ip address
|
||||
#LIMIT=4 # default 4 failed login attempts before blocking
|
||||
|
||||
# time between failed login attempts that are consecutive, in seconds, zero for DEFAULT
|
||||
#LIMIT_TIMEOUT=21600 # default 6 hours
|
||||
|
||||
# how long a blocked ip address stay blocks, in seconds, zero for DEFAULT
|
||||
#LIMIT_TTL=86400 # default 24 hours
|
||||
|
||||
# --- Extra Options ---
|
||||
# --- extra options ---
|
||||
|
||||
# how long do we allow *ALL* traffic from an ip address after successful login
|
||||
# could be useful if you have a system which does not handle cookies
|
||||
#IP_TTL=0 # default disabled, time in seconds
|
||||
|
||||
# if desired, in addition to supporting a TOTP, you can set a static password
|
||||
#STATIC_SECRET_ENABLED='0' # boolean, disabled by default
|
||||
#STATIC_SECRET='' # default disabled
|
||||
|
||||
# once blocked, do we respond with "I'm a teapot", false to use "Too many requests"
|
||||
#TEAPOT=true # default enabled, boolean
|
||||
|
||||
# --- Styling Options ---
|
||||
# --- rate limiting ---
|
||||
|
||||
# Note: rate limiting can *NOT* be disabled, but you could allow hundreds of logins a second
|
||||
# rate limiting, default is the lower of 2 per 30 seconds or 10 per hour
|
||||
#BURST_COUNT=2 # 2 per 30 seconds
|
||||
#BURST_TIME=30 # seconds
|
||||
#UPPER_COUNT=10 # 10 per hour
|
||||
#UPPER_TIME=3600 # seconds (1 hour)
|
||||
|
||||
# --- styling options ---
|
||||
|
||||
#TITLE='Pre-Authentication System'
|
||||
#BG_COLOR='#029386' # teal
|
||||
#FG_COLOR='#ffffff' # white
|
||||
@@ -49,3 +50,6 @@
|
||||
#TOO_MANY_TITLE='Too many requests'
|
||||
#TOO_MANY_MESSAGE='Try again later'
|
||||
|
||||
# --- debug options ---
|
||||
#SHELL_VERBOSITY=0 # set to "3" to log debug
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
|
||||
<!-- https://phpunit.readthedocs.io/en/latest/configuration.html -->
|
||||
<phpunit xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||
xsi:noNamespaceSchemaLocation="vendor/phpunit/phpunit/phpunit.xsd"
|
||||
colors="true"
|
||||
failOnDeprecation="true"
|
||||
failOnNotice="true"
|
||||
failOnWarning="true"
|
||||
bootstrap="tests/bootstrap.php"
|
||||
cacheDirectory=".phpunit.cache"
|
||||
>
|
||||
<php>
|
||||
<ini name="display_errors" value="1" />
|
||||
<ini name="error_reporting" value="-1" />
|
||||
<server name="APP_ENV" value="test" force="true" />
|
||||
<server name="SHELL_VERBOSITY" value="-1" />
|
||||
<server name="KERNEL_CLASS" value="App\Tests\TestKernel" />
|
||||
<!-- fixed TOTP secret so functional tests can compute valid codes -->
|
||||
<server name="TOTP_URI" value="otpauth://totp/Test-TOTP?secret=JBSWY3DPEHPK3PXP" />
|
||||
<server name="APP_SECRET" value="test_secret_key_change_me" />
|
||||
<!-- high rate limits so functional tests don't get blocked -->
|
||||
<server name="BURST_COUNT" value="10000" />
|
||||
<server name="UPPER_COUNT" value="10000" />
|
||||
</php>
|
||||
|
||||
<testsuites>
|
||||
<testsuite name="Project Test Suite">
|
||||
<directory>tests</directory>
|
||||
</testsuite>
|
||||
</testsuites>
|
||||
|
||||
<source ignoreSuppressionOfDeprecations="true"
|
||||
ignoreIndirectDeprecations="true"
|
||||
restrictNotices="true"
|
||||
restrictWarnings="true"
|
||||
>
|
||||
<include>
|
||||
<directory>src</directory>
|
||||
</include>
|
||||
|
||||
<deprecationTrigger>
|
||||
<function>trigger_deprecation</function>
|
||||
</deprecationTrigger>
|
||||
</source>
|
||||
|
||||
<extensions>
|
||||
</extensions>
|
||||
</phpunit>
|
||||
@@ -1,5 +1,7 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use App\Kernel;
|
||||
|
||||
require_once dirname(__DIR__).'/vendor/autoload_runtime.php';
|
||||
|
||||
@@ -7,6 +7,26 @@ So, I built a simple authentication gateway, which eventually turned into this p
|
||||
|
||||
It sits between your reverse proxy and web service to add extra protection, while still being easy to access from anywhere.
|
||||
|
||||
## Development
|
||||
|
||||
### Code Style
|
||||
|
||||
This project follows [PSR-12](https://www.php-fig.org/psr/psr-12/) and includes `php-cs-fixer` as a dev dependency.
|
||||
|
||||
```bash
|
||||
# Check for style violations
|
||||
vendor/bin/php-cs-fixer fix --dry-run --diff
|
||||
|
||||
# Auto-fix
|
||||
vendor/bin/php-cs-fixer fix
|
||||
```
|
||||
|
||||
### Running Tests
|
||||
|
||||
```bash
|
||||
vendor/bin/phpunit
|
||||
```
|
||||
|
||||
## Requirements
|
||||
|
||||
* Docker
|
||||
@@ -15,17 +35,36 @@ It sits between your reverse proxy and web service to add extra protection, whil
|
||||
|
||||
It may be possible to use some other reverse proxy, but for now, I'm going to stick with just Caddy.
|
||||
|
||||
There is an example Caddyfile in /docs/ and env.example file to get you started. Within the Caddyfile is a snippet, which makes it easy to wrap your web service with preauth.
|
||||
There is an example Caddyfile in /docs/ and an example.env file to get you started. Within the Caddyfile is a snippet, which makes it easy to wrap your web service with preauth.
|
||||
|
||||
When someone tries to reach your protected web service, Caddy will check with preauth if they are allowed, if their preauth cookie is missing, invalid, or expired, we will show them to a login screen.
|
||||
|
||||
I say login, but it's really just a TOTP code (6 digit code which changes every 30 second). But once they enter the right code,they'll get their cookie and be shown the protected service. It is also possible to allow all requests from an approved IP address, but that is disabled by default.
|
||||
I say login, but it's really just a TOTP code (6-digit code which changes every 30 second). But once they enter the right code,they'll get their cookie and be shown the protected service. It is also possible to allow all requests from an approved IP address, but that is disabled by default.
|
||||
|
||||
First time you spin up the docker container it will generate a TOTP secret (which you'll load into your authenticator app); or generate you own.
|
||||
|
||||
Be sure to save that TOTP secret to your docker environment, so that it persistents beyond removing the container.
|
||||
Be sure to save that TOTP secret to your docker environment, so that it persists beyond removing the container.
|
||||
|
||||
## Backup Codes
|
||||
|
||||
It is possible to generate single-use backup codes via a console command within the docker container.
|
||||
|
||||
```shell
|
||||
docker exec -t preauth bin/console app:generate-backup-codes [count=10]
|
||||
```
|
||||
|
||||
### History
|
||||
#### v0.7.0 (May 29th, 2026)
|
||||
Added ability to generate single-use backup codes.
|
||||
Removed static password and lookup token, as they were security risks.
|
||||
Updated to PHP 8.5, updated dependencies.
|
||||
|
||||
#### v0.6.0 (Feb 10th, 2026)
|
||||
Added optional (disabled by default) ability to lookup token by static password.
|
||||
|
||||
#### v0.5.0 (Jan 17th, 2026)
|
||||
Nonce related cleanup; added optional (disabled by default) ability to use a static password as a backup means of authentication.
|
||||
|
||||
#### v0.4.1 (Dec 26th, 2025)
|
||||
Fixed bug which can occur if you delete cache files.
|
||||
|
||||
|
||||
+5
-2
@@ -1,4 +1,5 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App;
|
||||
@@ -8,8 +9,10 @@ use Psr\Clock\ClockInterface;
|
||||
use Symfony\Component\DependencyInjection\Attribute\AsAlias;
|
||||
|
||||
#[AsAlias(ClockInterface::class)]
|
||||
final readonly class Clock implements ClockInterface {
|
||||
public function now(): DateTimeImmutable {
|
||||
final readonly class Clock implements ClockInterface
|
||||
{
|
||||
public function now(): DateTimeImmutable
|
||||
{
|
||||
return new DateTimeImmutable();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Command;
|
||||
|
||||
use App\PersistCache;
|
||||
use App\Service\BackupCodeInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Symfony\Component\Console\Command\Command;
|
||||
use Symfony\Component\Console\Input\InputArgument;
|
||||
use Symfony\Component\Console\Input\InputInterface;
|
||||
use Symfony\Component\Console\Output\OutputInterface;
|
||||
|
||||
/** simple console command to generate backup codes
|
||||
* usage: php bin/console app:generate-backup-codes [count] */
|
||||
final class GenerateBackupCodesCommand extends Command
|
||||
{
|
||||
public function __construct(
|
||||
private readonly BackupCodeInterface $manager,
|
||||
private readonly PersistCache $persistCache,
|
||||
) {
|
||||
parent::__construct();
|
||||
}
|
||||
|
||||
protected function configure(): void
|
||||
{
|
||||
$this->setName('app:generate-backup-codes');
|
||||
$this->setDescription('Generate single‑use backup codes')
|
||||
->addArgument('count', InputArgument::OPTIONAL, 'Number of codes to generate', 10);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
protected function execute(InputInterface $input, OutputInterface $output): int
|
||||
{
|
||||
/* since Kernel::terminate() does not get called, we must boot and persist explicitly */
|
||||
$this->persistCache->boot();
|
||||
$count = (int) $input->getArgument('count');
|
||||
$codes = $this->manager->generate($count);
|
||||
foreach ($codes as $code) {
|
||||
$output->writeln($code);
|
||||
}
|
||||
$this->persistCache->persist();
|
||||
return Command::SUCCESS;
|
||||
}
|
||||
}
|
||||
+34
-60
@@ -1,4 +1,5 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App;
|
||||
@@ -7,16 +8,12 @@ use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Clock\ClockInterface;
|
||||
use Symfony\Component\DependencyInjection\Attribute\Autowire;
|
||||
|
||||
final readonly class ConfigBag {
|
||||
final readonly class ConfigBag
|
||||
{
|
||||
private ClockInterface $clock;
|
||||
private int $cookieTtl;
|
||||
private int $limit;
|
||||
private int $limitTimeout;
|
||||
private int $limitTtl;
|
||||
private string $queryPrefix;
|
||||
private string $totpUri;
|
||||
private ?int $ipTtl;
|
||||
private ?string $staticSecret;
|
||||
private bool $teapot;
|
||||
private string $errorMessage;
|
||||
private string $teapotTitle;
|
||||
@@ -24,86 +21,63 @@ final readonly class ConfigBag {
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function __construct(
|
||||
Utilities $utilities,
|
||||
ClockInterface $clock,
|
||||
#[Autowire('%app.cookie_ttl%')] int $cookieTtl,
|
||||
#[Autowire('%app.limit%')] int $limit,
|
||||
#[Autowire('%app.limit_timeout%')] int $limitTimeout,
|
||||
#[Autowire('%app.limit_ttl%')] int $limitTtl,
|
||||
#[Autowire('%app.query_prefix%')] string $queryPrefix,
|
||||
#[Autowire('%app.totp_uri%')] string $totpUri,
|
||||
#[Autowire('%app.ip_ttl%')] ?int $ipTtl,
|
||||
#[Autowire('%app.static_secret_enabled%')] bool $staticSecretEnabled,
|
||||
#[Autowire('%app.static_secret%')] ?string $staticSecret,
|
||||
#[Autowire('%app.teapot%')] bool $teapot,
|
||||
#[Autowire('%app.error_message%')] string $errorMessage,
|
||||
#[Autowire('%app.teapot_title%')] string $teapotTitle,
|
||||
#[Autowire('%app.too_many_title%')] string $tooManyTitle,
|
||||
Utilities $utilities,
|
||||
ClockInterface $clock,
|
||||
#[Autowire('%app.cookie_ttl%')] int $cookieTtl,
|
||||
#[Autowire('%app.totp_uri%')] string $totpUri,
|
||||
#[Autowire('%app.ip_ttl%')] ?int $ipTtl,
|
||||
#[Autowire('%app.teapot%')] bool $teapot,
|
||||
#[Autowire('%app.error_message%')] string $errorMessage,
|
||||
#[Autowire('%app.teapot_title%')] string $teapotTitle,
|
||||
#[Autowire('%app.too_many_title%')] string $tooManyTitle,
|
||||
) {
|
||||
$this->clock = $clock;
|
||||
$this->cookieTtl = $cookieTtl;
|
||||
$this->limit = ($limit >= 1) ? $limit : 4;
|
||||
$this->limitTimeout = ($limitTimeout >= 1) ? $limitTimeout : 21600;
|
||||
$this->limitTtl = ($limitTtl >= 1) ? $limitTtl : 86400;
|
||||
$this->queryPrefix = $queryPrefix;
|
||||
$this->totpUri = $totpUri ?: $utilities->loadTotp();
|
||||
$this->ipTtl = $ipTtl ?: null;
|
||||
$this->staticSecret = $staticSecretEnabled ? ($staticSecret ?: null) : null;
|
||||
$this->teapot = $teapot;
|
||||
$this->clock = $clock;
|
||||
$this->cookieTtl = $cookieTtl;
|
||||
$this->totpUri = $totpUri ?: $utilities->loadTotp();
|
||||
$this->ipTtl = $ipTtl ?: null;
|
||||
$this->teapot = $teapot;
|
||||
$this->errorMessage = $errorMessage;
|
||||
$this->teapotTitle = $teapotTitle;
|
||||
$this->teapotTitle = $teapotTitle;
|
||||
$this->tooManyTitle = $tooManyTitle;
|
||||
}
|
||||
|
||||
public function clock(): ClockInterface {
|
||||
public function clock(): ClockInterface
|
||||
{
|
||||
return $this->clock;
|
||||
}
|
||||
|
||||
public function cookieTtl(): int {
|
||||
public function cookieTtl(): int
|
||||
{
|
||||
return $this->cookieTtl;
|
||||
}
|
||||
|
||||
public function limit(): int {
|
||||
return $this->limit;
|
||||
}
|
||||
|
||||
public function limitTimeout(): int {
|
||||
return $this->limitTimeout;
|
||||
}
|
||||
|
||||
public function limitTtl(): int {
|
||||
return $this->limitTtl;
|
||||
}
|
||||
|
||||
public function query(string $field): string {
|
||||
return "$this->queryPrefix$field";
|
||||
}
|
||||
|
||||
public function totpUri(): string {
|
||||
public function totpUri(): string
|
||||
{
|
||||
return $this->totpUri;
|
||||
}
|
||||
|
||||
public function ipTtl(): ?int {
|
||||
public function ipTtl(): ?int
|
||||
{
|
||||
return $this->ipTtl;
|
||||
}
|
||||
|
||||
public function staticSecret(): ?string {
|
||||
return $this->staticSecret;
|
||||
}
|
||||
|
||||
public function teapot(): bool {
|
||||
public function teapot(): bool
|
||||
{
|
||||
return $this->teapot;
|
||||
}
|
||||
|
||||
public function errorMessage(): string {
|
||||
public function errorMessage(): string
|
||||
{
|
||||
return $this->errorMessage;
|
||||
}
|
||||
|
||||
public function teapotTitle(): string {
|
||||
public function teapotTitle(): string
|
||||
{
|
||||
return $this->teapotTitle;
|
||||
}
|
||||
|
||||
public function tooManyTitle(): string {
|
||||
public function tooManyTitle(): string
|
||||
{
|
||||
return $this->tooManyTitle;
|
||||
}
|
||||
}
|
||||
|
||||
+45
-40
@@ -1,25 +1,27 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Data;
|
||||
|
||||
use App\Enum\Scope;
|
||||
use Symfony\Component\HttpFoundation\InputBag;
|
||||
|
||||
/* When scope is Ip but ip-access is disabled, scope is to be considered Cookie. */
|
||||
/* When using password but password is disabled, request will always fail. */
|
||||
final class Payload {
|
||||
public string $id; /* session name, identifying who is logging in */
|
||||
public ?string $token; /* totp, typically six digits */
|
||||
public ?string $password; /* static secret, alternative to token, if enabled */
|
||||
public string $nonce; /* random unique string, to block duplicate submissions */
|
||||
public bool $json; /* should we return json (for the login page) */
|
||||
public Scope $scope; /* type of access being requested */
|
||||
/** when scope is IP but ip-access is disabled, scope is to be considered cookie */
|
||||
final class Payload
|
||||
{
|
||||
public string $id; /* session name, identifying who is logging in */
|
||||
public string $token; /* TOTP, typically six digits */
|
||||
public string $nonce; /* random unique string, to block duplicate submissions */
|
||||
public bool $json; /* should we return json (for the login page) */
|
||||
public Scope $scope; /* type of access being requested */
|
||||
|
||||
public static function decode(string $base64url): ?Payload {
|
||||
public static function decode(string $base64url): ?Payload
|
||||
{
|
||||
/* convert the base64url into json string */
|
||||
$json = base64_decode(str_pad(strtr($base64url, '-_', '+/'),
|
||||
strlen($base64url) % 4, '='
|
||||
), true);
|
||||
$base64 = strtr($base64url, '-_', '+/');
|
||||
$base64 .= str_repeat('=', (4 - strlen($base64) % 4) % 4);
|
||||
$json = base64_decode($base64, true);
|
||||
if ($json) {
|
||||
/* convert the json string into real data */
|
||||
$data = json_decode($json);
|
||||
@@ -30,42 +32,49 @@ final class Payload {
|
||||
return null;
|
||||
}
|
||||
|
||||
public static function create(object $data): ?Payload {
|
||||
/* if missing required fields id or nonce */
|
||||
if (strlen($data->id ?? '') < 1 ||
|
||||
strlen($data->nonce ?? '') < 1 ||
|
||||
/* if missing both token and password (we require one of them) */
|
||||
(strlen($data->token ?? '') < 1 &&
|
||||
strlen($data->password ?? '') < 1)
|
||||
public static function load(InputBag $input): ?Payload
|
||||
{
|
||||
/* convert form data into real data */
|
||||
if ($input->has('username') && $input->has('nonce') && $input->has('totp')) {
|
||||
return Payload::create((object)[
|
||||
'id' => $input->get('username'),
|
||||
'nonce' => $input->get('nonce'),
|
||||
'token' => $input->get('totp'),
|
||||
'json' => false,
|
||||
]);
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
public static function create(object $data): ?Payload
|
||||
{
|
||||
/* if missing required fields id, nonce, or token */
|
||||
if (strlen(trim($data->id ?? '')) < 1 ||
|
||||
strlen(trim($data->nonce ?? '')) < 1 ||
|
||||
strlen(trim($data->token ?? '')) < 1
|
||||
) {
|
||||
/* returns null as the input is invalid */
|
||||
return null;
|
||||
}
|
||||
|
||||
/* all input is limited */
|
||||
$payload = new Payload();
|
||||
$payload->id = $data->id;
|
||||
$payload->nonce = $data->nonce;
|
||||
$payload->id = mb_substr(trim($data->id), 0, 128);
|
||||
$payload->nonce = mb_substr(trim($data->nonce), 0, 128);
|
||||
$payload->json = ($data->json ?? true);
|
||||
$payload->scope = Scope::tryFrom($data->scope ?? '') ?? Scope::Cookie;
|
||||
|
||||
/* we accept either a token or a password, not both */
|
||||
if (strlen($data->token ?? '') > 0) {
|
||||
$payload->token = $data->token;
|
||||
$payload->password = null;
|
||||
} else {
|
||||
$payload->token = null;
|
||||
$payload->password = $data->password;
|
||||
}
|
||||
$payload->token = mb_substr(trim($data->token), 0, 128);
|
||||
|
||||
return Payload::constrict($payload);
|
||||
}
|
||||
|
||||
public static function constrict(Payload $payload): Payload {
|
||||
/* When using password, scope will be considered None. */
|
||||
if ($payload->password) {
|
||||
$payload->scope = Scope::None;
|
||||
}
|
||||
public function toString(): string
|
||||
{
|
||||
return json_encode($this);
|
||||
}
|
||||
|
||||
private static function constrict(Payload $payload): Payload
|
||||
{
|
||||
/* When scope is None, json will be considered false. */
|
||||
if ($payload->scope === Scope::None) {
|
||||
$payload->json = false;
|
||||
@@ -73,8 +82,4 @@ final class Payload {
|
||||
|
||||
return $payload;
|
||||
}
|
||||
|
||||
public function toString(): string {
|
||||
return json_encode($this);
|
||||
}
|
||||
}
|
||||
|
||||
+4
-1
@@ -1,9 +1,12 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Enum;
|
||||
|
||||
enum Scope: string {
|
||||
/** scope defines the context of how a session is persisted */
|
||||
enum Scope: string
|
||||
{
|
||||
case Cookie = 'cookie';
|
||||
case Ip = 'ip';
|
||||
case None = 'none';
|
||||
|
||||
+7
-3
@@ -1,4 +1,5 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App;
|
||||
@@ -9,13 +10,15 @@ use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Kernel as BaseKernel;
|
||||
|
||||
final class Kernel extends BaseKernel {
|
||||
class Kernel extends BaseKernel
|
||||
{
|
||||
use MicroKernelTrait;
|
||||
|
||||
private PersistCache $persistCache;
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function boot(): void {
|
||||
public function boot(): void
|
||||
{
|
||||
parent::boot();
|
||||
|
||||
$this->persistCache = $this->container->get(PersistCache::class);
|
||||
@@ -23,7 +26,8 @@ final class Kernel extends BaseKernel {
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function terminate(Request $request, Response $response): void {
|
||||
public function terminate(Request $request, Response $response): void
|
||||
{
|
||||
$this->persistCache->persist();
|
||||
|
||||
parent::terminate($request, $response);
|
||||
|
||||
@@ -1,40 +1,48 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Listener;
|
||||
|
||||
use App\Service\DomainInterface;
|
||||
use App\Trait\CookieNameTrait;
|
||||
use App\Trait\HasLoggerTrait;
|
||||
use App\Trait\StringTrait;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Component\EventDispatcher\Attribute\AsEventListener;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
|
||||
final readonly class AcceptListener {
|
||||
final readonly class AcceptListener
|
||||
{
|
||||
use CookieNameTrait;
|
||||
use HasLoggerTrait;
|
||||
use StringTrait;
|
||||
|
||||
public function __construct(
|
||||
private CacheItemPoolInterface $sessionPool,
|
||||
private LoggerInterface $logger,
|
||||
) {}
|
||||
private CacheItemPoolInterface $sessionCache,
|
||||
private DomainInterface $domainManager,
|
||||
) {
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
#[AsEventListener(priority: 99)]
|
||||
public function onKernelRequest(RequestEvent $event): void {
|
||||
/* check if they sent the preauth cookie */
|
||||
if ($event->getRequest()->cookies->has($this->cookieName())) {
|
||||
$cookie = $event->getRequest()->cookies->get($this->cookieName());
|
||||
public function onKernelRequest(RequestEvent $event): void
|
||||
{
|
||||
/* check if they sent the correct preauth cookie */
|
||||
$cookieName = $this->domainManager->authBase() ? $this->authCookieName() : $this->cookieName();
|
||||
if ($event->getRequest()->cookies->has($cookieName)) {
|
||||
$cookie = $event->getRequest()->cookies->get($cookieName);
|
||||
$cookieKey = $this->makeCacheKey("cookie_$cookie");
|
||||
if ($this->sessionPool->hasItem($cookieKey)) {
|
||||
if ($cookie && $this->sessionCache->hasItem($cookieKey)) {
|
||||
/* cookie sent corresponds to valid existing session */
|
||||
$id = $this->sessionPool->getItem($cookieKey)->get();
|
||||
$id = $this->sessionCache->getItem($cookieKey)->get();
|
||||
$this->logger->debug("has valid cookie-session: $id");
|
||||
$event->setResponse(new Response("hi $id",
|
||||
headers: ['Content-Type' => 'text/plain']
|
||||
));
|
||||
$event->setResponse(new Response("hi $id", headers: [
|
||||
'Content-Type' => 'text/plain',
|
||||
'Remote-User' => $id,
|
||||
]));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,38 +1,43 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Listener;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Trait\HasLoggerTrait;
|
||||
use App\Trait\StringTrait;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Component\EventDispatcher\Attribute\AsEventListener;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
|
||||
final readonly class AllowListener {
|
||||
final readonly class AllowListener
|
||||
{
|
||||
use HasLoggerTrait;
|
||||
use StringTrait;
|
||||
|
||||
public function __construct(
|
||||
private CacheItemPoolInterface $sessionPool,
|
||||
private CacheItemPoolInterface $sessionCache,
|
||||
private ConfigBag $config,
|
||||
private LoggerInterface $logger,
|
||||
) {}
|
||||
) {
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
#[AsEventListener(priority: 88)]
|
||||
public function onKernelRequest(RequestEvent $event): void {
|
||||
public function onKernelRequest(RequestEvent $event): void
|
||||
{
|
||||
if ($this->config->ipTtl() > 0) {
|
||||
$ipKey = $this->makeCacheKey("ip_{$event->getRequest()->getClientIp()}");
|
||||
if ($this->sessionPool->hasItem($ipKey)) {
|
||||
if ($this->sessionCache->hasItem($ipKey)) {
|
||||
/* ip address corresponds to valid existing session */
|
||||
$id = $this->sessionPool->getItem($ipKey)->get();
|
||||
$id = $this->sessionCache->getItem($ipKey)->get();
|
||||
$this->logger->debug("has valid ip-session: $id");
|
||||
$event->setResponse(new Response("hi $id",
|
||||
headers: ['Content-Type' => 'text/plain']
|
||||
));
|
||||
$event->setResponse(new Response("hi $id", headers: [
|
||||
'Content-Type' => 'text/plain',
|
||||
'Remote-User' => $id,
|
||||
]));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Listener;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Service\DomainInterface;
|
||||
use App\Trait\CookieNameTrait;
|
||||
use App\Trait\HasLoggerTrait;
|
||||
use App\Trait\MakeNonceTrait;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Component\EventDispatcher\Attribute\AsEventListener;
|
||||
use Symfony\Component\HttpFoundation\Cookie;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Twig\Environment;
|
||||
@@ -16,34 +19,68 @@ use Twig\Error\LoaderError;
|
||||
use Twig\Error\RuntimeError;
|
||||
use Twig\Error\SyntaxError;
|
||||
|
||||
final readonly class InterceptListener {
|
||||
final readonly class InterceptListener
|
||||
{
|
||||
use CookieNameTrait;
|
||||
use HasLoggerTrait;
|
||||
use MakeNonceTrait;
|
||||
|
||||
public function __construct(
|
||||
private CacheItemPoolInterface $requestPool,
|
||||
private ConfigBag $config,
|
||||
private Environment $twig,
|
||||
CacheItemPoolInterface $noncePool,
|
||||
LoggerInterface $logger,
|
||||
private ConfigBag $config,
|
||||
private DomainInterface $domainManager,
|
||||
private Environment $twig,
|
||||
) {
|
||||
$this->logger = $logger;
|
||||
$this->noncePool = $noncePool;
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException|RuntimeError|SyntaxError|LoaderError */
|
||||
#[AsEventListener(priority: 55)]
|
||||
public function onKernelRequest(RequestEvent $event): void {
|
||||
if ($event->getRequest()) {
|
||||
/* by this point, we know that the request we have is:
|
||||
* not already authorized, nor already rate-limited,
|
||||
* nor submitting login credentials; so present the login page now */
|
||||
public function onKernelRequest(RequestEvent $event): void
|
||||
{
|
||||
/* by this point, we know that the request we have is:
|
||||
* not already authorized, nor already rate-limited,
|
||||
* nor submitting login credentials; so redirect or present the login page now */
|
||||
if ($this->domainManager->getAuthSubdomain() !== $event->getRequest()->getHost() &&
|
||||
$this->domainManager->matchesAuth($event->getRequest()->getHost())
|
||||
) {
|
||||
/* host matches base-domain of auth, but not on auth subdomain, redirect */
|
||||
$query = http_build_query(['return' => $event->getRequest()->getUri()]);
|
||||
$event->setResponse(new Response(
|
||||
'',
|
||||
Response::HTTP_SEE_OTHER,
|
||||
['Location' => "https://{$this->domainManager->getAuthSubdomain()}/?$query"]
|
||||
));
|
||||
} else {
|
||||
$this->logger->debug("presenting login page: {$event->getRequest()->getClientIp()}");
|
||||
$content = $this->twig->render('login.html.twig', [
|
||||
'nonce' => $this->makeNonce(),
|
||||
'post' => $this->domainManager->getAuthSubdomain() === $event->getRequest()->getHost(),
|
||||
]);
|
||||
$event->setResponse(new Response($content, Response::HTTP_UNAUTHORIZED,
|
||||
$hasCookie = (bool) $event->getRequest()->cookies->get(
|
||||
$this->domainManager->authBase() ? $this->authCookieName() : $this->cookieName()
|
||||
);
|
||||
$event->setResponse($this->pruneInvalidCookie(new Response(
|
||||
$content,
|
||||
Response::HTTP_UNAUTHORIZED,
|
||||
['Content-Type' => 'text/html']
|
||||
));
|
||||
), $hasCookie, $event->getRequest()->getHost()));
|
||||
}
|
||||
}
|
||||
|
||||
private function pruneInvalidCookie(Response $response, bool $hasCookie, string $host): Response
|
||||
{
|
||||
if ($hasCookie) {
|
||||
/* input here must match LoginListener::setCookie() */
|
||||
$response->headers->clearCookie(
|
||||
$this->domainManager->authBase() ? $this->authCookieName() : $this->cookieName(),
|
||||
'/',
|
||||
/* if using central auth, only set the domain if the host matches */
|
||||
$this->domainManager->matchesAuth($host) ? $this->domainManager->authBase() : null,
|
||||
true,
|
||||
true,
|
||||
Cookie::SAMESITE_STRICT
|
||||
);
|
||||
}
|
||||
|
||||
return $response;
|
||||
}
|
||||
}
|
||||
|
||||
+53
-195
@@ -1,235 +1,101 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Listener;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Data\Payload;
|
||||
use App\Enum\Scope;
|
||||
use App\MonitorCacheKeys;
|
||||
use App\Service\DomainInterface;
|
||||
use App\Service\LoginInterface;
|
||||
use App\Trait\CookieNameTrait;
|
||||
use App\Trait\HasLoggerTrait;
|
||||
use App\Trait\MakeNonceTrait;
|
||||
use App\Trait\StringTrait;
|
||||
use OTPHP\Factory;
|
||||
use OTPHP\TOTPInterface;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Component\DependencyInjection\Attribute\Target;
|
||||
use Symfony\Component\EventDispatcher\Attribute\AsEventListener;
|
||||
use Symfony\Component\HttpFoundation\Cookie;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
use Symfony\Component\Uid\Ulid;
|
||||
use Symfony\Component\RateLimiter\RateLimiterFactoryInterface;
|
||||
use Twig\Environment;
|
||||
use Twig\Error\LoaderError;
|
||||
use Twig\Error\RuntimeError;
|
||||
use Twig\Error\SyntaxError;
|
||||
|
||||
final readonly class LoginListener {
|
||||
final readonly class LoginListener
|
||||
{
|
||||
use CookieNameTrait;
|
||||
use HasLoggerTrait;
|
||||
use MakeNonceTrait;
|
||||
use StringTrait;
|
||||
|
||||
private CacheItemPoolInterface $requestPool;
|
||||
private CacheItemPoolInterface $sessionPool;
|
||||
private RateLimiterFactoryInterface $rateLimiter;
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function __construct(
|
||||
private ConfigBag $config,
|
||||
private Environment $twig,
|
||||
CacheItemPoolInterface $noncePool,
|
||||
CacheItemPoolInterface $requestPool,
|
||||
CacheItemPoolInterface $sessionPool,
|
||||
LoggerInterface $logger,
|
||||
private Environment $twig,
|
||||
#[Target('login_limiter')] RateLimiterFactoryInterface $rateLimiter,
|
||||
private DomainInterface $domainManager,
|
||||
private LoginInterface $loginManager,
|
||||
private ConfigBag $config,
|
||||
) {
|
||||
$this->requestPool = new MonitorCacheKeys($requestPool);
|
||||
$this->sessionPool = new MonitorCacheKeys($sessionPool);
|
||||
$this->noncePool = $noncePool;
|
||||
$this->logger = $logger;
|
||||
$this->rateLimiter = $rateLimiter;
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException|LoaderError|RuntimeError|SyntaxError */
|
||||
#[AsEventListener(priority: 66)]
|
||||
public function onKernelRequest(RequestEvent $event): void {
|
||||
public function onKernelRequest(RequestEvent $event): void
|
||||
{
|
||||
$payload = null;
|
||||
$response = null;
|
||||
|
||||
if ($event->getRequest()->headers->has($this->headerName())) {
|
||||
/* if request contains our "X-Preauth" header */
|
||||
$data = $event->getRequest()->headers->get($this->headerName());
|
||||
$payload = Payload::decode($data);
|
||||
$response = null;
|
||||
if ($payload) {
|
||||
/* if using token */
|
||||
if ($payload->token) {
|
||||
$response = $this->checkToken($payload, $event->getRequest());
|
||||
} else if ($this->config->staticSecret()) {
|
||||
$response = $this->checkPassword($payload);
|
||||
}
|
||||
}
|
||||
} elseif ($event->getRequest()->isMethod(Request::METHOD_POST) &&
|
||||
$this->domainManager->getAuthSubdomain() === $event->getRequest()->getHost()
|
||||
) {
|
||||
/* if request is a POST to the auth-subdomain */
|
||||
$payload = Payload::load($event->getRequest()->getPayload());
|
||||
} else {
|
||||
/* no login attempt detected */
|
||||
return;
|
||||
}
|
||||
|
||||
/* token or password authentication was successful */
|
||||
if ($payload) {
|
||||
/* user sent a valid payload, check it */
|
||||
$response = $this->loginManager->checkToken($payload, $event->getRequest());
|
||||
|
||||
/* token or backup-code authentication was successful */
|
||||
if ($response) {
|
||||
$event->setResponse($response);
|
||||
return;
|
||||
}
|
||||
|
||||
$limitReached = $this->logFailure(
|
||||
$payload ? $payload->toString() : $data,
|
||||
$event->getRequest()
|
||||
);
|
||||
|
||||
$this->logger->debug("logging failure for: {$event->getRequest()->getClientIp()}");
|
||||
$event->setResponse($this->makeFailedResponse($limitReached, $payload->json ?? true));
|
||||
}
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function checkToken(Payload $payload, Request $request): ?Response {
|
||||
/* When scope is Ip but ip-access is disabled, scope will be considered Cookie. */
|
||||
if ($payload->scope === Scope::Ip && ! $this->config->ipTtl()) {
|
||||
/* requested to grant ip access, but that is not enabled */
|
||||
$payload->scope = Scope::Cookie;
|
||||
}
|
||||
|
||||
if ($this->getTotp()->verify($payload->token, null, 10)) {
|
||||
/* token is correct */
|
||||
/* login attempted but unsuccessful, log and block if needed */
|
||||
$limitReached = $this->logFailure($event->getRequest());
|
||||
|
||||
/* if server nonce is found and is valid */
|
||||
$nonceItem = $this->noncePool->getItem($payload->nonce);
|
||||
if ($nonceItem->isHit() && $nonceItem->get()) {
|
||||
/* mark nonce as spent */
|
||||
$nonceItem->set(false); /* invalid */
|
||||
$nonceItem->expiresAfter(static::NONCE_TTL); /* keep breifly */
|
||||
$this->noncePool->save($nonceItem);
|
||||
|
||||
/* token authentication successful, grant access and set response */
|
||||
$cleanId = $this->makeCacheKey($payload->id);
|
||||
|
||||
/* if they just want this one page, return ok, to grant them access */
|
||||
$response = new Response("hi $cleanId",
|
||||
headers: ['Content-Type' => 'text/plain']
|
||||
);
|
||||
|
||||
if ($payload->scope !== Scope::None) {
|
||||
/* grant access based on the requested scope */
|
||||
if ($payload->scope === Scope::Cookie) {
|
||||
$response->headers->setCookie($this->setCookie($cleanId));
|
||||
} else if ($payload->scope === Scope::Ip) {
|
||||
$this->setIp($cleanId, $request->getClientIp());
|
||||
}
|
||||
|
||||
if ($payload->json) {
|
||||
$contentType = 'application/json';
|
||||
$content = json_encode([
|
||||
'message' => 'Login successful',
|
||||
'nonce' => null,
|
||||
]);
|
||||
} else {
|
||||
$contentType = 'text/html';
|
||||
$content = "hi $cleanId, please reload";
|
||||
}
|
||||
|
||||
$response->setContent($content)
|
||||
->setStatusCode(Response::HTTP_TEMPORARY_REDIRECT)
|
||||
->headers->set('Location',
|
||||
"{$request->getPathInfo()}{$request->getQueryString()}"
|
||||
);
|
||||
$response->headers->set('Content-Type', $contentType);
|
||||
}
|
||||
|
||||
$this->logger->debug("successful login for: $cleanId");
|
||||
return $response;
|
||||
}
|
||||
}
|
||||
return null;
|
||||
$this->logger->debug("logging failure for: {$event->getRequest()->getClientIp()}");
|
||||
$event->setResponse($this->makeFailedResponse(
|
||||
$limitReached,
|
||||
$payload->json ?? true,
|
||||
$event->getRequest()->getHost(),
|
||||
$this->makeCacheKey($payload ? $payload->id : '')
|
||||
));
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function checkPassword(Payload $payload): ?Response {
|
||||
/* When using password but password is disabled, request will always fail. */
|
||||
|
||||
/* if password is correct */
|
||||
|
||||
if (hash_equals($this->config->staticSecret(), $payload->password)) {
|
||||
/* password is correct */
|
||||
|
||||
/* nonce *may* be client provided, but must still be unique */
|
||||
|
||||
/* if server/client nonce is acceptable (valid server or unused client) */
|
||||
$nonceItem = $this->noncePool->getItem($payload->nonce);
|
||||
if (($nonceItem->isHit() && $nonceItem->get()) || ! $nonceItem->isHit()) {
|
||||
/* mark nonce as spent */
|
||||
$nonceItem->set(false); /* invalid */
|
||||
$nonceItem->expiresAfter(static::NONCE_TTL); /* keep breifly */
|
||||
$this->noncePool->save($nonceItem);
|
||||
|
||||
/* password authentication successful, grant access and set response */
|
||||
$cleanId = $this->makeCacheKey($payload->id);
|
||||
$this->logger->debug("successful login for: $cleanId");
|
||||
return new Response("hi $cleanId",
|
||||
headers: ['Content-Type' => 'text/plain']
|
||||
);
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function setCookie(string $id): Cookie {
|
||||
/* successful auth with token, store session and set the cookie */
|
||||
$ulid = new Ulid();
|
||||
$sessionCookie = $this->sessionPool->getItem(
|
||||
$this->makeCacheKey("cookie_$ulid")
|
||||
);
|
||||
if ($sessionCookie->isHit()) {
|
||||
/* it is supposed to be impossible to have collisions */
|
||||
$this->logger->error("aborting: ULID collision");
|
||||
throw new HttpException(Response::HTTP_INTERNAL_SERVER_ERROR, 'Internal Server Error');
|
||||
}
|
||||
$sessionCookie->set($id);
|
||||
$sessionCookie->expiresAfter($this->config->cookieTtl());
|
||||
$this->sessionPool->save($sessionCookie);
|
||||
|
||||
return Cookie::create(
|
||||
name: $this->cookieName(),
|
||||
value: $ulid->toString(),
|
||||
expire: time() + $this->config->cookieTtl(),
|
||||
secure: true,
|
||||
sameSite: Cookie::SAMESITE_STRICT
|
||||
);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function setIp(string $id, string $ip): void {
|
||||
/* successful auth with token, requested scope of ip (and ip access enabled) */
|
||||
$ipKey = $this->makeCacheKey("ip_$ip");
|
||||
|
||||
$sessionIp = $this->sessionPool->getItem($ipKey);
|
||||
$sessionIp->set($id);
|
||||
$sessionIp->expiresAfter($this->config->ipTtl());
|
||||
$this->sessionPool->save($sessionIp);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function logFailure(string $data, Request $request): bool {
|
||||
// TODO use rate-limiting symfony system (also update RejectListener)
|
||||
$timeframe = (int)floor(time() / $this->getTotp()->getPeriod());
|
||||
/* hash the data and timeframe, so we do not count duplicates in the same timeframe
|
||||
* hitting refresh a few times should not lock you out */
|
||||
$ipKey = $this->makeCacheKey("ip_{$request->getClientIp()}");
|
||||
$failuresItem = $this->requestPool->getItem($ipKey);
|
||||
$failures = $failuresItem->get() ?? [];
|
||||
$failures[hash('xxh3', "$timeframe-$data")] = true;
|
||||
$limitReached = count($failures) >= $this->config->limit();
|
||||
$failuresItem->set($failures);
|
||||
$failuresItem->expiresAfter($limitReached
|
||||
? $this->config->limitTtl() : $this->config->limitTimeout()
|
||||
);
|
||||
$this->requestPool->save($failuresItem);
|
||||
return $limitReached;
|
||||
private function logFailure(Request $request): bool
|
||||
{
|
||||
$limiter = $this->rateLimiter->create($request->getClientIp());
|
||||
return ($limiter->consume(1)->getRemainingTokens() < 1);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException|RuntimeError|SyntaxError|LoaderError */
|
||||
private function makeFailedResponse(bool $limited, bool $json): Response {
|
||||
private function makeFailedResponse(bool $limited, bool $json, string $host, string $username): Response
|
||||
{
|
||||
if ($limited) {
|
||||
$status = $this->config->teapot() ? Response::HTTP_I_AM_A_TEAPOT
|
||||
: Response::HTTP_TOO_MANY_REQUESTS;
|
||||
@@ -242,6 +108,8 @@ final readonly class LoginListener {
|
||||
$answer = [
|
||||
'message' => $message,
|
||||
'nonce' => $this->makeNonce(),
|
||||
'post' => $this->domainManager->getAuthSubdomain() === $host,
|
||||
'username' => $username,
|
||||
];
|
||||
|
||||
if ($json) {
|
||||
@@ -254,14 +122,4 @@ final readonly class LoginListener {
|
||||
|
||||
return new Response($content, $status, ["Content-Type" => $contentType]);
|
||||
}
|
||||
|
||||
private function getTotp(): TOTPInterface {
|
||||
$otp = Factory::loadFromProvisioningUri(
|
||||
$this->config->totpUri(), $this->config->clock()
|
||||
);
|
||||
if ($otp instanceof TOTPInterface) {
|
||||
return $otp;
|
||||
}
|
||||
throw new HttpException(500, 'Internal Server Exception');
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,48 +1,52 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Listener;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Trait\HasLoggerTrait;
|
||||
use App\Trait\StringTrait;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Component\DependencyInjection\Attribute\Target;
|
||||
use Symfony\Component\EventDispatcher\Attribute\AsEventListener;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\RateLimiter\RateLimiterFactoryInterface;
|
||||
use Twig\Environment;
|
||||
use Twig\Error\LoaderError;
|
||||
use Twig\Error\RuntimeError;
|
||||
use Twig\Error\SyntaxError;
|
||||
|
||||
final readonly class RejectListener {
|
||||
final readonly class RejectListener
|
||||
{
|
||||
use HasLoggerTrait;
|
||||
use StringTrait;
|
||||
|
||||
private RateLimiterFactoryInterface $rateLimiter;
|
||||
|
||||
public function __construct(
|
||||
private CacheItemPoolInterface $requestPool,
|
||||
private ConfigBag $config,
|
||||
private Environment $twig,
|
||||
private LoggerInterface $logger,
|
||||
) {}
|
||||
private ConfigBag $config,
|
||||
private Environment $twig,
|
||||
#[Target('login_limiter')] RateLimiterFactoryInterface $rateLimiter,
|
||||
) {
|
||||
$this->rateLimiter = $rateLimiter;
|
||||
}
|
||||
|
||||
/** @throws SyntaxError|InvalidArgumentException|RuntimeError|LoaderError */
|
||||
/** @throws SyntaxError|RuntimeError|LoaderError */
|
||||
#[AsEventListener(priority: 77)]
|
||||
public function onKernelRequest(RequestEvent $event): void {
|
||||
$ipKey = $this->makeCacheKey("ip_{$event->getRequest()->getClientIp()}");
|
||||
|
||||
public function onKernelRequest(RequestEvent $event): void
|
||||
{
|
||||
/* check if they have made too many failed login attempts */
|
||||
$failuresItem = $this->requestPool->getItem($ipKey);
|
||||
if ($failuresItem->isHit()) {
|
||||
$failures = $failuresItem->get() ?? [];
|
||||
if (count($failures) >= $this->config->limit()) {
|
||||
$this->logger->debug("already blocked: {$event->getRequest()->getClientIp()}");
|
||||
$html = $this->twig->render('error.html.twig');
|
||||
$event->setResponse(new Response($html, ($this->config->teapot()
|
||||
? Response::HTTP_I_AM_A_TEAPOT : Response::HTTP_TOO_MANY_REQUESTS),
|
||||
['Content-Type' => 'text/html']
|
||||
));
|
||||
}
|
||||
$limiter = $this->rateLimiter->create($event->getRequest()->getClientIp());
|
||||
if ($limiter->consume(0)->getRemainingTokens() < 1) {
|
||||
$this->logger->debug("already blocked: {$event->getRequest()->getClientIp()}");
|
||||
$html = $this->twig->render('error.html.twig');
|
||||
$event->setResponse(new Response(
|
||||
$html,
|
||||
($this->config->teapot()
|
||||
? Response::HTTP_I_AM_A_TEAPOT : Response::HTTP_TOO_MANY_REQUESTS),
|
||||
['Content-Type' => 'text/html']
|
||||
));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+92
-59
@@ -1,4 +1,5 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App;
|
||||
@@ -8,20 +9,24 @@ use Psr\Cache\CacheItemInterface;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
|
||||
/* We must not store the key-list item or values within this object,
|
||||
* because it can change from outside this object instance. */
|
||||
final readonly class MonitorCacheKeys implements CacheItemPoolInterface {
|
||||
private const KEY_LIST = '__key_list';
|
||||
private const IS_DIRTY = '__is_dirty';
|
||||
/* we must *NOT* store the key-list item or values within this object
|
||||
* because it can change from outside this object instance */
|
||||
final readonly class MonitorCacheKeys implements CacheItemPoolInterface
|
||||
{
|
||||
private const string KEY_LIST = '__key_list';
|
||||
private const string CHANGE_LIST = '__chg_list';
|
||||
public const int UPDATED = 1;
|
||||
public const int REMOVED = 2;
|
||||
|
||||
private CacheItemPoolInterface $cache;
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function __construct(CacheItemPoolInterface $cache) {
|
||||
public function __construct(CacheItemPoolInterface $cache)
|
||||
{
|
||||
$this->cache = $cache;
|
||||
$items = $cache->getItems([self::KEY_LIST, self::IS_DIRTY]);
|
||||
$items = $cache->getItems([self::KEY_LIST, self::CHANGE_LIST]);
|
||||
foreach ($items as $item) {
|
||||
if ( ! $item->isHit()) {
|
||||
if (! $item->isHit()) {
|
||||
$this->initialize();
|
||||
break;
|
||||
}
|
||||
@@ -29,51 +34,61 @@ final readonly class MonitorCacheKeys implements CacheItemPoolInterface {
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function initialize(): void {
|
||||
private function initialize(): void
|
||||
{
|
||||
$keyList = $this->cache->getItem(self::KEY_LIST);
|
||||
$isDirty = $this->cache->getItem(self::IS_DIRTY);
|
||||
$changeList = $this->cache->getItem(self::CHANGE_LIST);
|
||||
$keyList->set([]);
|
||||
$isDirty->set(false);
|
||||
$changeList->set([]);
|
||||
$this->cache->saveDeferred($keyList);
|
||||
$this->cache->saveDeferred($isDirty);
|
||||
$this->cache->saveDeferred($changeList);
|
||||
$this->cache->commit();
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function getKeys(): array {
|
||||
public function getKeys(): array
|
||||
{
|
||||
$keyList = $this->cache->getItem(self::KEY_LIST);
|
||||
return array_keys($keyList->get() ?? []);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function isDirty(): bool {
|
||||
$isDirty = $this->cache->getItem(self::IS_DIRTY);
|
||||
return $isDirty->get() ?? false;
|
||||
public function getChanges(): array
|
||||
{
|
||||
$changeList = $this->cache->getItem(self::CHANGE_LIST);
|
||||
return $changeList->get() ?? [];
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function markClean(): void {
|
||||
$isDirty = $this->cache->getItem(self::IS_DIRTY);
|
||||
$isDirty->set(false);
|
||||
$this->cache->save($isDirty);
|
||||
public function markClean(): void
|
||||
{
|
||||
$changeList = $this->cache->getItem(self::CHANGE_LIST);
|
||||
$changeList->set([]);
|
||||
$this->cache->save($changeList);
|
||||
}
|
||||
|
||||
public function getItem(string $key): CacheItemInterface {
|
||||
public function getItem(string $key): CacheItemInterface
|
||||
{
|
||||
return $this->cache->getItem($key);
|
||||
}
|
||||
|
||||
public function getItems(array $keys = []): iterable {
|
||||
/** @return CacheItemInterface[]
|
||||
* @throws InvalidArgumentException */
|
||||
public function getItems(array $keys = []): iterable
|
||||
{
|
||||
return $this->cache->getItems($keys);
|
||||
}
|
||||
|
||||
public function hasItem(string $key): bool {
|
||||
public function hasItem(string $key): bool
|
||||
{
|
||||
return $this->cache->hasItem($key);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function clear(): bool {
|
||||
public function clear(): bool
|
||||
{
|
||||
/* only bother clearing the pool if it is not empty */
|
||||
if ( ! empty($this->getKeys())) {
|
||||
if (! empty($this->getKeys())) {
|
||||
$response = $this->cache->clear();
|
||||
|
||||
$this->initialize();
|
||||
@@ -82,83 +97,101 @@ final readonly class MonitorCacheKeys implements CacheItemPoolInterface {
|
||||
return true;
|
||||
}
|
||||
|
||||
public function deleteItem(string $key): bool {
|
||||
if ($key === self::KEY_LIST || $key === self::IS_DIRTY) {
|
||||
throw new OutOfBoundsException(
|
||||
'Can not delete the private key list or is dirty flag'
|
||||
);
|
||||
}
|
||||
public function deleteItem(string $key): bool
|
||||
{
|
||||
$this->isValid($key);
|
||||
$keyList = $this->cache->getItem(self::KEY_LIST);
|
||||
$isDirty = $this->cache->getItem(self::IS_DIRTY);
|
||||
$keyValues = $keyList->get();
|
||||
if (isset($keyValues[$key])) {
|
||||
unset($keyValues[$key]);
|
||||
$keyList->set($keyValues);
|
||||
$isDirty->set(true);
|
||||
$this->cache->saveDeferred($keyList);
|
||||
$this->cache->saveDeferred($isDirty);
|
||||
$this->logChange($key, MonitorCacheKeys::REMOVED);
|
||||
$this->cache->commit();
|
||||
}
|
||||
|
||||
return $this->cache->deleteItem($key);
|
||||
}
|
||||
|
||||
public function deleteItems(array $keys): bool {
|
||||
if (in_array(self::KEY_LIST, $keys, true) ||
|
||||
in_array(self::IS_DIRTY, $keys, true)
|
||||
) {
|
||||
throw new OutOfBoundsException(
|
||||
'Can not delete the private key list or is dirty flag'
|
||||
);
|
||||
}
|
||||
public function deleteItems(array $keys): bool
|
||||
{
|
||||
$this->allValid($keys);
|
||||
$keyList = $this->cache->getItem(self::KEY_LIST);
|
||||
$isDirty = $this->cache->getItem(self::IS_DIRTY);
|
||||
$keyValues = $keyList->get();
|
||||
foreach ($keys as $key) {
|
||||
if (isset($keyValues[$key])) {
|
||||
unset($keyValues[$key]);
|
||||
$isDirty->set(true);
|
||||
$this->logChange($key, MonitorCacheKeys::REMOVED);
|
||||
}
|
||||
}
|
||||
$keyList->set($keyValues);
|
||||
$this->cache->saveDeferred($keyList);
|
||||
$this->cache->saveDeferred($isDirty);
|
||||
$this->cache->commit();
|
||||
|
||||
return $this->cache->deleteItems($keys);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function save(CacheItemInterface $item): bool {
|
||||
public function save(CacheItemInterface $item): bool
|
||||
{
|
||||
$this->update($item);
|
||||
return $this->cache->save($item);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function saveDeferred(CacheItemInterface $item): bool {
|
||||
public function saveDeferred(CacheItemInterface $item): bool
|
||||
{
|
||||
$this->update($item);
|
||||
return $this->cache->saveDeferred($item);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function update(CacheItemInterface $item) {
|
||||
if ($item->getKey() === self::KEY_LIST || $item->getKey() === self::IS_DIRTY) {
|
||||
throw new OutOfBoundsException(
|
||||
'Can not alter the private key list or is dirty flag'
|
||||
);
|
||||
}
|
||||
public function commit(): bool
|
||||
{
|
||||
return $this->cache->commit();
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException|OutOfBoundsException */
|
||||
private function update(CacheItemInterface $item): void
|
||||
{
|
||||
$this->isValid($item->getKey());
|
||||
$keyList = $this->cache->getItem(self::KEY_LIST);
|
||||
$isDirty = $this->cache->getItem(self::IS_DIRTY);
|
||||
$keyValues = $keyList->get();
|
||||
$keyValues[$item->getKey()] = true;
|
||||
$keyList->set($keyValues);
|
||||
$isDirty->set(true);
|
||||
$this->logChange($item->getKey());
|
||||
$this->cache->saveDeferred($keyList);
|
||||
$this->cache->saveDeferred($isDirty);
|
||||
$this->cache->commit();
|
||||
}
|
||||
|
||||
public function commit(): bool {
|
||||
return $this->cache->commit();
|
||||
/** @throws OutOfBoundsException */
|
||||
private function isValid(string $key): void
|
||||
{
|
||||
if ($key === self::KEY_LIST || $key === self::CHANGE_LIST) {
|
||||
throw new OutOfBoundsException(
|
||||
'Can not modify the private key or change lists'
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/** @throws OutOfBoundsException */
|
||||
private function allValid(array $keys): void
|
||||
{
|
||||
if (in_array(self::KEY_LIST, $keys, true) ||
|
||||
in_array(self::CHANGE_LIST, $keys, true)
|
||||
) {
|
||||
throw new OutOfBoundsException(
|
||||
'Can not modify the private key or change lists'
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function logChange(string $key, int $code = MonitorCacheKeys::UPDATED): void
|
||||
{
|
||||
$changeList = $this->cache->getItem(self::CHANGE_LIST);
|
||||
$changeValues = $changeList->get();
|
||||
$changeValues[$key] = $code;
|
||||
$changeList->set($changeValues);
|
||||
$this->cache->saveDeferred($changeList);
|
||||
}
|
||||
}
|
||||
|
||||
+30
-46
@@ -1,4 +1,5 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App;
|
||||
@@ -7,69 +8,52 @@ use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Symfony\Component\DependencyInjection\Attribute\Autoconfigure;
|
||||
|
||||
/* need autoconfigure so we get it from the service container in Kernel->boot() */
|
||||
#[Autoconfigure(public: true)]
|
||||
final readonly class PersistCache {
|
||||
private MonitorCacheKeys $requestPool;
|
||||
private MonitorCacheKeys $persistRequestPool;
|
||||
private MonitorCacheKeys $sessionPool;
|
||||
private MonitorCacheKeys $persistSessionPool;
|
||||
final readonly class PersistCache
|
||||
{
|
||||
private MonitorCacheKeys $sessionCache;
|
||||
private MonitorCacheKeys $sessionStorage;
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function __construct(
|
||||
CacheItemPoolInterface $requestPool,
|
||||
CacheItemPoolInterface $persistRequestPool,
|
||||
CacheItemPoolInterface $sessionPool,
|
||||
CacheItemPoolInterface $persistSessionPool
|
||||
CacheItemPoolInterface $sessionCache,
|
||||
CacheItemPoolInterface $sessionStorage,
|
||||
) {
|
||||
$this->requestPool = new MonitorCacheKeys($requestPool);
|
||||
$this->persistRequestPool = new MonitorCacheKeys($persistRequestPool);
|
||||
$this->sessionPool = new MonitorCacheKeys($sessionPool);
|
||||
$this->persistSessionPool = new MonitorCacheKeys($persistSessionPool);
|
||||
$this->sessionCache = new MonitorCacheKeys($sessionCache);
|
||||
$this->sessionStorage = new MonitorCacheKeys($sessionStorage);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function boot(): void {
|
||||
public function boot(): void
|
||||
{
|
||||
/* the caches are considered warm as soon as they are not empty */
|
||||
if (empty($this->requestPool->getKeys())) {
|
||||
$items = $this->persistRequestPool->getItems($this->persistRequestPool->getKeys());
|
||||
if (empty($this->sessionCache->getKeys())) {
|
||||
$items = $this->sessionStorage->getItems($this->sessionStorage->getKeys());
|
||||
foreach ($items as $item) {
|
||||
$this->requestPool->saveDeferred($item);
|
||||
$this->sessionCache->saveDeferred($item);
|
||||
}
|
||||
$this->requestPool->markClean();
|
||||
$this->requestPool->commit();
|
||||
}
|
||||
|
||||
if (empty($this->sessionPool->getKeys())) {
|
||||
$items = $this->persistSessionPool->getItems($this->persistSessionPool->getKeys());
|
||||
foreach ($items as $item) {
|
||||
$this->sessionPool->saveDeferred($item);
|
||||
}
|
||||
$this->sessionPool->markClean();
|
||||
$this->sessionPool->commit();
|
||||
$this->sessionCache->markClean();
|
||||
$this->sessionCache->commit();
|
||||
}
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function persist(): void {
|
||||
/* we only need to persist the caches if they contain changes */
|
||||
if ($this->requestPool->isDirty()) {
|
||||
$this->requestPool->markClean();
|
||||
$items = $this->requestPool->getItems($this->requestPool->getKeys());
|
||||
$this->persistRequestPool->clear();
|
||||
public function persist(): void
|
||||
{
|
||||
/* we only need to persist the changes made to the cache (if any) */
|
||||
$changes = $this->sessionCache->getChanges();
|
||||
if ($changes) {
|
||||
$this->sessionCache->markClean();
|
||||
$items = $this->sessionCache->getItems(array_keys($changes));
|
||||
foreach ($items as $item) {
|
||||
$this->persistRequestPool->saveDeferred($item);
|
||||
if (($changes[$item->getKey()] ?? null) === MonitorCacheKeys::REMOVED) {
|
||||
$this->sessionStorage->deleteItem($item->getKey());
|
||||
} else {
|
||||
$this->sessionStorage->saveDeferred($item);
|
||||
}
|
||||
}
|
||||
$this->persistRequestPool->commit();
|
||||
}
|
||||
|
||||
if ($this->sessionPool->isDirty()) {
|
||||
$this->sessionPool->markClean();
|
||||
$items = $this->sessionPool->getItems($this->sessionPool->getKeys());
|
||||
$this->persistSessionPool->clear();
|
||||
foreach ($items as $item) {
|
||||
$this->persistSessionPool->saveDeferred($item);
|
||||
}
|
||||
$this->persistSessionPool->commit();
|
||||
$this->sessionStorage->commit();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
<?php
|
||||
|
||||
namespace App\Service;
|
||||
|
||||
use Exception;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
|
||||
/** backup-codes are case‑insensitive alphanumeric strings
|
||||
* they are single-use and marked as used after successful authentication */
|
||||
interface BackupCodeInterface
|
||||
{
|
||||
/** generate a set of backup-codes and return them
|
||||
* @param int $count Number of codes to generate
|
||||
* @return string[] Generated backup codes
|
||||
* @throws InvalidArgumentException|Exception */
|
||||
public function generate(int $count = 0): array;
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function expire(): void;
|
||||
|
||||
/** check if backup-code is valid and mark it as used
|
||||
* @param string $code Code supplied by the client
|
||||
* @return bool true if the code is valid and unused
|
||||
* @throws InvalidArgumentException */
|
||||
public function verifyAndConsume(string $code): bool;
|
||||
}
|
||||
@@ -0,0 +1,113 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Service;
|
||||
|
||||
use App\MonitorCacheKeys;
|
||||
use App\Trait\HasLoggerTrait;
|
||||
use App\Trait\StringTrait;
|
||||
use DateTimeImmutable;
|
||||
use Exception;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use App\Trait\GetTotpTrait;
|
||||
|
||||
/** backup-codes are case‑insensitive alphanumeric strings
|
||||
* they are single-use and marked as used after successful authentication */
|
||||
final readonly class BackupCodeManager implements BackupCodeInterface
|
||||
{
|
||||
use GetTotpTrait;
|
||||
use HasLoggerTrait;
|
||||
use StringTrait;
|
||||
|
||||
private const int DEFAULT_COUNT = 10;
|
||||
/* php base_convert() will break if given too long of an input */
|
||||
public const int MAX_LENGTH = 64;
|
||||
|
||||
private CacheItemPoolInterface $sessionCache;
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function __construct(CacheItemPoolInterface $sessionCache)
|
||||
{
|
||||
$this->sessionCache = new MonitorCacheKeys($sessionCache);
|
||||
}
|
||||
|
||||
/** generate a set of backup-codes and return them
|
||||
* @param int $count Number of codes to generate
|
||||
* @return string[] Generated backup codes
|
||||
* @throws InvalidArgumentException|Exception */
|
||||
public function generate(int $count = self::DEFAULT_COUNT): array
|
||||
{
|
||||
$length = min($this->getTotp()->getDigits() + 2, self::MAX_LENGTH);
|
||||
$codes = [];
|
||||
for ($i = 0; $i < $count; $i++) {
|
||||
/* output is alphanumeric string of given length */
|
||||
$codes[] = strtolower(str_pad(substr(base_convert(bin2hex(
|
||||
random_bytes($length)
|
||||
), 16, 36), 0, $length), $length, '0', STR_PAD_LEFT));
|
||||
}
|
||||
$this->saveCodes($codes);
|
||||
$this->logger->info("generated {$count} backup codes");
|
||||
return $codes;
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function expire(): void
|
||||
{
|
||||
$itemsToRemove = [];
|
||||
foreach ($this->sessionCache->getKeys() as $key) {
|
||||
if (str_starts_with($key, 'backup_')) {
|
||||
$itemsToRemove[] = $key;
|
||||
}
|
||||
}
|
||||
if (count($itemsToRemove) > 0) {
|
||||
$this->sessionCache->deleteItems($itemsToRemove);
|
||||
}
|
||||
}
|
||||
|
||||
/** check if backup-code is valid and mark it as used
|
||||
* @param string $code Code supplied by the client
|
||||
* @return bool true if the code is valid and unused
|
||||
* @throws InvalidArgumentException */
|
||||
public function verifyAndConsume(string $code): bool
|
||||
{
|
||||
/* remove unallowed characters, since backup codes are case-insensitive alphanumeric */
|
||||
$backupKey = 'backup_' . preg_replace('/[^a-z0-9]+/', '', strtolower($code));
|
||||
$backupItem = $this->sessionCache->getItem($this->makeCacheKey($backupKey));
|
||||
$this->logger->debug("checking backup code '{$backupKey}': " . ($backupItem->isHit() ? 'HIT & ' : 'miss & ') . ($backupItem->get() ? 'VALID' : 'invalid'));
|
||||
if ($backupItem->isHit() && $backupItem->get()) {
|
||||
$this->logger->debug("valid backup code");
|
||||
/* mark backup code as spent */
|
||||
$backupItem->set(false); /* used */
|
||||
/* per PSR6, if no expiration is set, implementation may set a default,
|
||||
* we want this to keep forever, so a few hundred years should do it */
|
||||
$backupItem->expiresAt(DateTimeImmutable::createFromFormat(
|
||||
'Y-m-d',
|
||||
'2999-12-31'
|
||||
));
|
||||
$this->sessionCache->save($backupItem);
|
||||
|
||||
return true;
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function saveCodes(array $codes): void
|
||||
{
|
||||
foreach ($codes as $code) {
|
||||
$backupItem = $this->sessionCache->getItem($this->makeCacheKey(strtolower("backup_$code")));
|
||||
/* mark backup code as ready */
|
||||
$backupItem->set(true);
|
||||
/* per PSR6, if no expiration is set, implementation may set a default,
|
||||
* we want this to keep forever, so a few hundred years should do it */
|
||||
$backupItem->expiresAt(DateTimeImmutable::createFromFormat(
|
||||
'Y-m-d',
|
||||
'2999-12-31'
|
||||
));
|
||||
$this->sessionCache->saveDeferred($backupItem);
|
||||
}
|
||||
$this->sessionCache->commit();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,24 @@
|
||||
<?php
|
||||
|
||||
namespace App\Service;
|
||||
|
||||
interface DomainInterface
|
||||
{
|
||||
/** IE: "auth.example.com" or null if not using a separate subdomain
|
||||
* @return ?string Returns auth subdomain if configured, otherwise null */
|
||||
public function getAuthSubdomain(): ?string;
|
||||
|
||||
/** check if given url is an acceptable url for redirection
|
||||
* @param string $url Where we are thinking of sending the user
|
||||
* @return bool Returns true if it is acceptable to send the user there */
|
||||
public function validReturn(string $url): bool;
|
||||
|
||||
/** check if host-base matches auth-base
|
||||
* @param string $host
|
||||
* @return bool returns true if and only if host matches base domain of auth */
|
||||
public function matchesAuth(string $host): bool;
|
||||
|
||||
/** IE: "example.com" if central auth is something like "auth.example.com"
|
||||
* @return string|null returns base domain if we are doing central auth */
|
||||
public function authBase(): ?string;
|
||||
}
|
||||
@@ -0,0 +1,128 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Service;
|
||||
|
||||
use Symfony\Component\DependencyInjection\Attribute\Autowire;
|
||||
|
||||
final readonly class DomainManager implements DomainInterface
|
||||
{
|
||||
/* top-level-domains which are known to have multiple parts */
|
||||
private const array TLD = [
|
||||
'ai' => ['com','net','off','org'],
|
||||
'am' => ['radio'],
|
||||
'com' => ['br','cn','co','de','eu','gr','it','jpn','mex','ru','sa','uk','us','za'],
|
||||
'de' => ['com'],
|
||||
'fm' => ['radio'],
|
||||
'gg' => ['co','net','org'],
|
||||
'in' => ['co','firm','gen','ind','net','org'],
|
||||
'je' => ['co','net','org'],
|
||||
'mx' => ['com','net','org'],
|
||||
'net' => ['gb','hu','in','jp','se','uk'],
|
||||
'nz' => ['co','net','org'],
|
||||
'org' => ['ae','us'],
|
||||
'ph' => ['com','net','org'],
|
||||
'se' => ['com'],
|
||||
'uk' => ['co','me','org'],
|
||||
];
|
||||
|
||||
private bool $subdomainRedirect;
|
||||
private string $authSubdomain;
|
||||
|
||||
public function __construct(
|
||||
#[Autowire('%app.subdomain_redirect%')] bool $subdomainRedirect,
|
||||
#[Autowire('%app.auth_subdomain%')] string $authSubdomain,
|
||||
) {
|
||||
$this->subdomainRedirect = $subdomainRedirect;
|
||||
$this->authSubdomain = $authSubdomain;
|
||||
}
|
||||
|
||||
/** IE: "auth.example.com" or null if not using a separate subdomain
|
||||
* @return ?string Returns auth subdomain if configured, otherwise null */
|
||||
public function getAuthSubdomain(): ?string
|
||||
{
|
||||
if ($this->authBase()) {
|
||||
return $this->authSubdomain;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
/** check if given url is an acceptable url for redirection
|
||||
* @param string $url Where we are thinking of sending the user
|
||||
* @return bool Returns true if it is acceptable to send the user there */
|
||||
public function validReturn(string $url): bool
|
||||
{
|
||||
/* ensure url is valid and, when using an auth subdomain,
|
||||
* that the url host matches the base domain */
|
||||
if (!filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if ($this->authBase()) {
|
||||
$host = parse_url($url, PHP_URL_HOST);
|
||||
if ($host === null) {
|
||||
return false;
|
||||
}
|
||||
/* do not send the user to another domain */
|
||||
return $this->matchesAuth($host);
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/** check if host-base matches auth-base
|
||||
* @param string $host
|
||||
* @return bool returns true if and only if host matches base domain of auth */
|
||||
public function matchesAuth(string $host): bool
|
||||
{
|
||||
$hostBase = $this->baseDomain($host);
|
||||
$authBase = $this->baseDomain($this->authSubdomain);
|
||||
return $this->subdomainRedirect && $this->authSubdomain &&
|
||||
$authBase && $authBase === $hostBase;
|
||||
}
|
||||
|
||||
/** IE: "example.com" if central auth is something like "auth.example.com"
|
||||
* @return string|null returns base domain if we are doing central auth */
|
||||
public function authBase(): ?string
|
||||
{
|
||||
if ($this->subdomainRedirect && $this->authSubdomain && $this->baseDomain($this->authSubdomain)) {
|
||||
return $this->baseDomain($this->authSubdomain);
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
/** this lets us determine the base domain of the given ip, localhost, or domain
|
||||
* "service.example.co.uk" into "example.co.uk" and "service.example.com" into "example.com"
|
||||
* things like "localhost" and "8.8.8.8" will return null
|
||||
* @param string $host ip, localhost, or domain with zero or more subdomains
|
||||
* @return ?string returns null if host is ip or localhost otherwise domain with all subdomains removed */
|
||||
private function baseDomain(string $host): ?string
|
||||
{
|
||||
/* if host is an ip address (or localhost), leave it as is */
|
||||
if (filter_var($host, FILTER_VALIDATE_IP) || $host === 'localhost') {
|
||||
return null;
|
||||
}
|
||||
|
||||
$parts = explode('.', $host);
|
||||
$keep = $this->baseLength($parts);
|
||||
$parts = array_slice($parts, -$keep);
|
||||
return implode('.', $parts);
|
||||
}
|
||||
|
||||
/** IE: ["www", "example", "com"] or ["www", "example", "co", "uk"]
|
||||
* @param string[] $parts pieces of a domain split by "." dot
|
||||
* @return int typically 2 but sometimes 3 */
|
||||
private function baseLength(array $parts): int
|
||||
{
|
||||
$length = count($parts);
|
||||
$baseLength = min(2, $length);
|
||||
/* check if host should retain 3 parts, due to TLD */
|
||||
if (count($parts) > 2 && isset(self::TLD[$parts[$length - 1]]) &&
|
||||
in_array($parts[$length - 2], self::TLD[$parts[$length - 1]], true)
|
||||
) {
|
||||
$baseLength = min(3, $length);
|
||||
}
|
||||
return $baseLength;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
<?php
|
||||
|
||||
namespace App\Service;
|
||||
|
||||
use App\Data\Payload;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
|
||||
interface LoginInterface
|
||||
{
|
||||
/** @throws InvalidArgumentException */
|
||||
public function checkToken(Payload $payload, Request $request): ?Response;
|
||||
}
|
||||
@@ -0,0 +1,153 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Service;
|
||||
|
||||
use App\Data\Payload;
|
||||
use App\Enum\Scope;
|
||||
use App\MonitorCacheKeys;
|
||||
use App\Trait\CookieNameTrait;
|
||||
use App\Trait\GetTotpTrait;
|
||||
use App\Trait\MakeNonceTrait;
|
||||
use App\Trait\StringTrait;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Symfony\Component\HttpFoundation\Cookie;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
use Symfony\Component\Uid\Ulid;
|
||||
|
||||
final readonly class LoginManager implements LoginInterface
|
||||
{
|
||||
use CookieNameTrait;
|
||||
use GetTotpTrait;
|
||||
use MakeNonceTrait;
|
||||
use StringTrait;
|
||||
|
||||
private CacheItemPoolInterface $sessionCache;
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function __construct(
|
||||
CacheItemPoolInterface $sessionCache,
|
||||
private BackupCodeInterface $backupCodeManager,
|
||||
private DomainInterface $domainManager,
|
||||
) {
|
||||
$this->sessionCache = new MonitorCacheKeys($sessionCache);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function checkToken(Payload $payload, Request $request): ?Response
|
||||
{
|
||||
/* when scope is IP but ip-access is disabled, scope is to be considered cookie */
|
||||
if ($payload->scope === Scope::Ip && ! $this->config->ipTtl()) {
|
||||
/* requested to grant ip access, but that is not enabled */
|
||||
$payload->scope = Scope::Cookie;
|
||||
}
|
||||
|
||||
if ($this->getTotp()->verify($payload->token, null, 10) ||
|
||||
$this->backupCodeManager->verifyAndConsume($payload->token)
|
||||
) {
|
||||
/* token is correct (TOTP or Backup) */
|
||||
|
||||
/* if server nonce is found and is valid */
|
||||
$nonceItem = $this->nonceCache->getItem($this->makeCacheKey($payload->nonce));
|
||||
if ($nonceItem->isHit() && $nonceItem->get()) {
|
||||
/* mark nonce as spent */
|
||||
$nonceItem->set(false); /* invalid */
|
||||
$nonceItem->expiresAfter(LoginManager::NONCE_TTL); /* keep briefly */
|
||||
$this->nonceCache->save($nonceItem);
|
||||
|
||||
/* token authentication successful, grant access and set response */
|
||||
$cleanId = $this->makeCacheKey($payload->id);
|
||||
|
||||
/* if they just want this one page, return ok, to grant them access */
|
||||
$response = new Response("hi $cleanId", headers: [
|
||||
'Content-Type' => 'text/plain',
|
||||
'Remote-User' => $cleanId,
|
||||
]);
|
||||
|
||||
if ($payload->scope !== Scope::None) {
|
||||
/* grant access based on the requested scope */
|
||||
if ($payload->scope === Scope::Cookie) {
|
||||
$response->headers->setCookie($this->setCookie($cleanId, $request->getHost()));
|
||||
} elseif ($payload->scope === Scope::Ip) {
|
||||
$this->setIp($cleanId, $request->getClientIp());
|
||||
}
|
||||
|
||||
if ($payload->json) {
|
||||
$contentType = 'application/json';
|
||||
$content = json_encode([
|
||||
'message' => 'Login successful',
|
||||
'nonce' => null,
|
||||
]);
|
||||
} else {
|
||||
$contentType = 'text/html';
|
||||
$content = "hi $cleanId, please reload";
|
||||
}
|
||||
|
||||
$location = $request->query->has('return') &&
|
||||
$this->domainManager->validReturn($request->query->get('return')) ?
|
||||
"{$request->query->get('return')}" :
|
||||
"{$request->getPathInfo()}{$request->getQueryString()}";
|
||||
|
||||
/* force redirect to use GET method (important when using central auth) */
|
||||
$response->setContent($content)
|
||||
->setStatusCode(Response::HTTP_SEE_OTHER)
|
||||
->headers->set('Location', $location);
|
||||
$response->headers->set('Content-Type', $contentType);
|
||||
}
|
||||
|
||||
$this->logger->debug("successful login for: $cleanId");
|
||||
return $response;
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function setCookie(string $id, string $host): Cookie
|
||||
{
|
||||
/* successful auth with token, store session and set the cookie */
|
||||
$ulid = new Ulid();
|
||||
$sessionCookie = $this->sessionCache->getItem(
|
||||
$this->makeCacheKey("cookie_$ulid")
|
||||
);
|
||||
if ($sessionCookie->isHit()) {
|
||||
/* it is supposed to be impossible to have collisions */
|
||||
$this->logger->error("aborting: ULID collision");
|
||||
throw new HttpException(Response::HTTP_INTERNAL_SERVER_ERROR, 'Internal Server Error');
|
||||
}
|
||||
$sessionCookie->set($id);
|
||||
$sessionCookie->expiresAfter($this->config->cookieTtl());
|
||||
$this->sessionCache->save($sessionCookie);
|
||||
|
||||
/* when using subdomain-auth we have to use a different cookie name, as the
|
||||
* "__Host-Http-" prefix we normally use does not allow domain to be set */
|
||||
/* changes here must be reflected in InterceptListener::pruneInvalidCookie() */
|
||||
return Cookie::create(
|
||||
name: $this->domainManager->authBase() ? $this->authCookieName() : $this->cookieName(),
|
||||
value: $ulid->toString(),
|
||||
expire: time() + $this->config->cookieTtl(),
|
||||
path: '/',
|
||||
/* if using central auth, only set the domain if the host matches */
|
||||
domain: $this->domainManager->matchesAuth($host) ? $this->domainManager->authBase() : null,
|
||||
secure: true,
|
||||
httpOnly: true,
|
||||
sameSite: Cookie::SAMESITE_STRICT,
|
||||
);
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function setIp(string $id, string $ip): void
|
||||
{
|
||||
/* successful auth with token, requested scope of ip (and ip access enabled) */
|
||||
$ipKey = $this->makeCacheKey("ip_$ip");
|
||||
|
||||
$sessionIp = $this->sessionCache->getItem($ipKey);
|
||||
$sessionIp->set($id);
|
||||
$sessionIp->expiresAfter($this->config->ipTtl());
|
||||
$this->sessionCache->save($sessionIp);
|
||||
}
|
||||
}
|
||||
@@ -1,17 +1,27 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Trait;
|
||||
|
||||
trait CookieNameTrait {
|
||||
private const COOKIE_NAME = '__Host-Http-Preauth';
|
||||
private const HEADER_NAME = 'X-Preauth';
|
||||
trait CookieNameTrait
|
||||
{
|
||||
private const string COOKIE_NAME = '__Host-Http-Preauth';
|
||||
private const string AUTH_COOKIE_NAME = '__Http-Domain-Preauth';
|
||||
private const string HEADER_NAME = 'X-Preauth';
|
||||
|
||||
final protected function cookieName(): string {
|
||||
final protected function cookieName(): string
|
||||
{
|
||||
return static::COOKIE_NAME;
|
||||
}
|
||||
|
||||
final protected function headerName(): string {
|
||||
final protected function authCookieName(): string
|
||||
{
|
||||
return static::AUTH_COOKIE_NAME;
|
||||
}
|
||||
|
||||
final protected function headerName(): string
|
||||
{
|
||||
return static::HEADER_NAME;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Trait;
|
||||
|
||||
use App\ConfigBag;
|
||||
use OTPHP\Factory;
|
||||
use OTPHP\TOTPInterface;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
use Symfony\Contracts\Service\Attribute\Required;
|
||||
|
||||
trait GetTotpTrait
|
||||
{
|
||||
protected readonly ConfigBag $config;
|
||||
|
||||
#[Required]
|
||||
public function setConfig(ConfigBag $config): void
|
||||
{
|
||||
$this->config = $config;
|
||||
}
|
||||
|
||||
protected function getTotp(): TOTPInterface
|
||||
{
|
||||
$otp = Factory::loadFromProvisioningUri(
|
||||
$this->config->totpUri(),
|
||||
$this->config->clock()
|
||||
);
|
||||
if ($otp instanceof TOTPInterface) {
|
||||
return $otp;
|
||||
}
|
||||
throw new HttpException(500, 'Internal Server Exception');
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Trait;
|
||||
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Contracts\Service\Attribute\Required;
|
||||
|
||||
trait HasLoggerTrait
|
||||
{
|
||||
protected readonly LoggerInterface $logger;
|
||||
|
||||
#[Required]
|
||||
public function setLogger(LoggerInterface $logger): void
|
||||
{
|
||||
$this->logger = $logger;
|
||||
}
|
||||
}
|
||||
@@ -1,4 +1,5 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Trait;
|
||||
@@ -6,25 +7,35 @@ namespace App\Trait;
|
||||
use Exception;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
use Symfony\Contracts\Service\Attribute\Required;
|
||||
|
||||
trait MakeNonceTrait
|
||||
{
|
||||
use HasLoggerTrait;
|
||||
use StringTrait;
|
||||
|
||||
trait MakeNonceTrait {
|
||||
/* 15 bytes neatly fits in base64 */
|
||||
private const NONCE_LENGTH = 15;
|
||||
private const NONCE_TTL = 120;
|
||||
private const int NONCE_LENGTH = 15;
|
||||
private const int NONCE_TTL = 120;
|
||||
|
||||
protected readonly CacheItemPoolInterface $noncePool;
|
||||
protected readonly LoggerInterface $logger;
|
||||
protected readonly CacheItemPoolInterface $nonceCache;
|
||||
|
||||
#[Required]
|
||||
public function setNonceCache(CacheItemPoolInterface $nonceCache): void
|
||||
{
|
||||
$this->nonceCache = $nonceCache;
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException|Exception */
|
||||
protected function makeNonce(int $retries = 3): string {
|
||||
protected function makeNonce(int $retries = 3): string
|
||||
{
|
||||
/* convert raw binary into base64url */
|
||||
$nonce = rtrim(strtr(base64_encode(random_bytes(
|
||||
static::NONCE_LENGTH
|
||||
)), '+/', '-_'), '=');
|
||||
$nonceItem = $this->noncePool->getItem($nonce);
|
||||
$nonceItem = $this->nonceCache->getItem($this->makeCacheKey($nonce));
|
||||
|
||||
if ($nonceItem->isHit()) {
|
||||
if ($retries < 1) {
|
||||
@@ -41,7 +52,7 @@ trait MakeNonceTrait {
|
||||
$nonceItem->set(true); /* valid */
|
||||
$nonceItem->expiresAfter(static::NONCE_TTL);
|
||||
$this->logger->debug("added nonce: $nonce");
|
||||
$this->noncePool->save($nonceItem);
|
||||
$this->nonceCache->save($nonceItem);
|
||||
return $nonce;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,13 +1,16 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Trait;
|
||||
|
||||
trait StringTrait {
|
||||
trait StringTrait
|
||||
{
|
||||
/* cache keys can safely use alphanumeric, "_", and ".", remove the rest */
|
||||
private const KEY_REGEX = '/[^A-Za-z0-9_.]+/';
|
||||
private const string KEY_REGEX = '/[^A-Za-z0-9_.]+/';
|
||||
|
||||
public function makeCacheKey(string $name): string {
|
||||
return preg_replace(static::KEY_REGEX, '_', $name);
|
||||
public function makeCacheKey(string $name): string
|
||||
{
|
||||
return mb_substr(preg_replace(static::KEY_REGEX, '_', $name), 0, 128);
|
||||
}
|
||||
}
|
||||
|
||||
+18
-15
@@ -1,4 +1,5 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App;
|
||||
@@ -11,14 +12,17 @@ use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Cache\InvalidArgumentException;
|
||||
use Psr\Clock\ClockInterface;
|
||||
|
||||
final readonly class Utilities {
|
||||
final readonly class Utilities
|
||||
{
|
||||
public function __construct(
|
||||
private ClockInterface $clock,
|
||||
private CacheItemPoolInterface $appPool,
|
||||
) {}
|
||||
) {
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
public function loadTotp(): string {
|
||||
public function loadTotp(): string
|
||||
{
|
||||
/* user forgot to set their TOTP_URI in the environment */
|
||||
if ($this->appPool->hasItem('totp')) {
|
||||
$totp = $this->appPool->getItem('totp')->get();
|
||||
@@ -31,7 +35,8 @@ final readonly class Utilities {
|
||||
}
|
||||
|
||||
/** @throws InvalidArgumentException */
|
||||
private function makeTotp(): string {
|
||||
private function makeTotp(): string
|
||||
{
|
||||
/* we have not stored a totp into the app cache yet */
|
||||
$totpObj = TOTP::generate($this->clock);
|
||||
$totpObj->setLabel('Preauth-TOTP');
|
||||
@@ -41,27 +46,25 @@ final readonly class Utilities {
|
||||
/* per PSR6, if no expiration is set, implementation may set a default,
|
||||
* we want this to keep forever, so a few hundred years should do it */
|
||||
$totpItem->expiresAt(DateTimeImmutable::createFromFormat(
|
||||
'Y-m-d', '2999-12-31'
|
||||
'Y-m-d',
|
||||
'2999-12-31'
|
||||
));
|
||||
$this->appPool->save($totpItem);
|
||||
return $totp;
|
||||
}
|
||||
|
||||
private function showTotp(string $totp): void {
|
||||
// /* only show this at most, every 5 minutes */
|
||||
// $suppress = $this->appPool->getItem('suppress');
|
||||
// if ( ! $suppress->isHit()) {
|
||||
private function showTotp(string $totp): void
|
||||
{
|
||||
$writer = new Writer(new PlainTextRenderer());
|
||||
file_put_contents(
|
||||
'php://stderr', <<<RAW
|
||||
'php://stderr',
|
||||
<<<RAW
|
||||
{$writer->writeString($totp)}
|
||||
$totp
|
||||
loading totp, because the env is not set, please copy above into TOTP_URI
|
||||
loading TOTP, because the env is not set, please copy above into TOTP_URI
|
||||
|
||||
RAW, FILE_APPEND
|
||||
RAW,
|
||||
FILE_APPEND
|
||||
);
|
||||
// $suppress->expiresAfter(300);
|
||||
// $this->appPool->save($suppress);
|
||||
// }
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
0
|
||||
__key_list
|
||||
a:0:{}
|
||||
@@ -1,3 +0,0 @@
|
||||
0
|
||||
__is_dirty
|
||||
b:0;
|
||||
@@ -1,3 +0,0 @@
|
||||
0
|
||||
__key_list
|
||||
a:0:{}
|
||||
@@ -1,3 +0,0 @@
|
||||
0
|
||||
__is_dirty
|
||||
b:0;
|
||||
@@ -1,3 +0,0 @@
|
||||
1766103213
|
||||
suppress
|
||||
N;
|
||||
@@ -1,3 +0,0 @@
|
||||
32503594112
|
||||
totp
|
||||
s:138:"otpauth://totp/Preauth-TOTP?secret=5RL5FOJGV4XRKGT74ZVN4725OAM244SU7JYXYX4SHQDTJI4P3YKBYAFUVBBOCLI5XSOLERNB6IQQ54SIGY6QHJ26JM4OP3ZJVBUUBIY";
|
||||
@@ -1,4 +1,31 @@
|
||||
{
|
||||
"friendsofphp/php-cs-fixer": {
|
||||
"version": "3.95",
|
||||
"recipe": {
|
||||
"repo": "github.com/symfony/recipes",
|
||||
"branch": "main",
|
||||
"version": "3.39",
|
||||
"ref": "97aaf9026490db73b86c23d49e5774bc89d2b232"
|
||||
},
|
||||
"files": [
|
||||
".php-cs-fixer.dist.php"
|
||||
]
|
||||
},
|
||||
"phpunit/phpunit": {
|
||||
"version": "13.2",
|
||||
"recipe": {
|
||||
"repo": "github.com/symfony/recipes",
|
||||
"branch": "main",
|
||||
"version": "11.1",
|
||||
"ref": "ca0bc067abfb40a8de1b2561b96cbfc2b833c314"
|
||||
},
|
||||
"files": [
|
||||
".env.test",
|
||||
"phpunit.dist.xml",
|
||||
"tests/bootstrap.php",
|
||||
"bin/phpunit"
|
||||
]
|
||||
},
|
||||
"symfony/console": {
|
||||
"version": "7.4",
|
||||
"recipe": {
|
||||
|
||||
@@ -0,0 +1,84 @@
|
||||
<script>
|
||||
const form = document.getElementById('preauth-form');
|
||||
const message = document.getElementById('preauth-message');
|
||||
const body = document.getElementById('preauth-body');
|
||||
const style = document.getElementById('preauth-style');
|
||||
|
||||
form.addEventListener('submit', (event) => {
|
||||
event.preventDefault();
|
||||
|
||||
{# make base64url string containing our payload json object #}
|
||||
const data = btoa(JSON.stringify({
|
||||
id: form.username.value?.trim() ?? '',
|
||||
token: form.totp.value?.trim() ?? '',
|
||||
nonce: form.nonce.value?.trim() ?? '',
|
||||
json: true
|
||||
})).replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '');
|
||||
|
||||
{# send our request to the server #}
|
||||
fetch(window.location.href, {
|
||||
method: 'GET',
|
||||
headers: { 'X-Preauth': data },
|
||||
}).then((response) => {
|
||||
{% if env.debug > 2 -%}
|
||||
console.log(response);
|
||||
{% endif -%}
|
||||
if (response.headers.has('Location')) {
|
||||
{# follow redirect (probably not needed) #}
|
||||
{% if env.debug > 2 -%}
|
||||
console.log('got redirect response');
|
||||
{% endif -%}
|
||||
window.location.href = response.headers.get('Location');
|
||||
} else if (response.headers.get('Content-Type')?.toLowerCase().includes('application/json') ?? false) {
|
||||
{# got json, update the page #}
|
||||
{% if env.debug > 2 -%}
|
||||
console.log('got json response');
|
||||
{% endif -%}
|
||||
response.json().then((content) => {
|
||||
if (Object.hasOwn(content, 'message')) {
|
||||
message.innerText = content.message;
|
||||
}
|
||||
if (Object.hasOwn(content, 'nonce')) {
|
||||
form.nonce.value = content.nonce;
|
||||
form.totp.value = '';
|
||||
form.totp.focus();
|
||||
}
|
||||
}).catch((error) => {
|
||||
console.log('failed to parse json from response');
|
||||
console.log(error);
|
||||
});
|
||||
} else if (response.headers.get('Content-Type')?.toLowerCase().includes('text/html') ?? false) {
|
||||
{# got html, replace the page #}
|
||||
{% if env.debug > 2 -%}
|
||||
console.log('got html response');
|
||||
{% endif -%}
|
||||
response.text().then((html) => {
|
||||
document.open();
|
||||
document.write(html);
|
||||
document.close();
|
||||
}).catch((error) => {
|
||||
console.log('failed to get html from response');
|
||||
console.log(error);
|
||||
});
|
||||
} else {
|
||||
{# non-json, non-html, non-redirect response #}
|
||||
{# update the page, change style to plain text #}
|
||||
{% if env.debug > 2 -%}
|
||||
console.log('got misc response');
|
||||
{% endif -%}
|
||||
response.text().then((text) => {
|
||||
body.innerText = text;
|
||||
style.disabled = true;
|
||||
body.style.whiteSpace = 'pre-wrap';
|
||||
body.style.wordWrap = 'break-word';
|
||||
}).catch((error) => {
|
||||
console.log('failed to get text from response');
|
||||
console.log(error);
|
||||
});
|
||||
}
|
||||
}).catch((error) => {
|
||||
console.log('failed to get response');
|
||||
console.log(error);
|
||||
});
|
||||
});
|
||||
</script>
|
||||
@@ -1,4 +1,4 @@
|
||||
<style>
|
||||
<style id="preauth-style">
|
||||
* { margin: 0; padding: 0.25em; }
|
||||
html { background-color: {{ env.bg_color }}; color: {{ env.fg_color }}; display: table;
|
||||
font-family: sans-serif; font-size: 1.5em; height: 100%; padding: 0; width: 100%; }
|
||||
|
||||
@@ -4,9 +4,9 @@
|
||||
<meta charset="utf-8">
|
||||
<title>{{ env.title }}</title>
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1">
|
||||
{{ include('_style.html.twig') }}
|
||||
{{- include('_style.html.twig') -}}
|
||||
</head>
|
||||
<body>
|
||||
<body id="preauth-body">
|
||||
{% block content %}{% endblock %}
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+10
-116
@@ -3,123 +3,17 @@
|
||||
{% block content %}
|
||||
<h1>{{ env.title }}</h1>
|
||||
<p id="preauth-message">{{ message|default }}</p>
|
||||
<form id="preauth-form">
|
||||
<input id="preauth-nonce" type="hidden" name="preauth_nonce" value="{{ nonce }}">
|
||||
<div class="right"><label for="preauth-id">{{ env.id_name }}:</label></div>
|
||||
<div><input type="text" name="preauth_id" id="preauth-id"
|
||||
autocomplete="username" required="required" autofocus="autofocus"></div>
|
||||
{% if env.allow_password %}
|
||||
<div class="right boxTk">
|
||||
<label for="preauth-token">{{ env.token_name }}:</label><br>
|
||||
<span id="preauth-use-pw">🔃 {{ env.password_name }}</span></div>
|
||||
<div class="boxTk"><input type="text" name="preauth_token" id="preauth-token"
|
||||
autocomplete="one-time-code" required="required"></div>
|
||||
|
||||
<div class="right boxPw hidden">
|
||||
<label for="preauth-password">{{ env.password_name }}:</label><br>
|
||||
<span id="preauth-use-tk">🔃 {{ env.token_name }}</span></div>
|
||||
<div class="boxPw hidden"><input type="password" name="preauth_password" id="preauth-password"
|
||||
autocomplete="password" disabled="disabled" required="required"></div>
|
||||
{% else %}
|
||||
<div class="right"><label for="preauth-token">{{ env.token_name }}:</label></div>
|
||||
<div><input type="text" name="preauth_token" id="preauth-token"
|
||||
autocomplete="one-time-code" required="required"></div>
|
||||
{% endif %}
|
||||
<form id="preauth-form" {% if post ?? false -%} method="post" {%- endif %}>
|
||||
<input id="nonce" type="hidden" name="nonce" value="{{ nonce }}">
|
||||
<div class="right"><label for="username">{{ env.id_name }}:</label></div>
|
||||
<div><input type="text" name="username" id="username" {% if username ?? false %}value="{{ username }}"{% endif %}
|
||||
autocomplete="username" required="required" autofocus="autofocus"></div>
|
||||
<div class="right"><label for="totp">{{ env.token_name }}:</label></div>
|
||||
<div><input type="text" name="totp" id="totp"
|
||||
autocomplete="one-time-code" required="required"></div>
|
||||
<div class="center"><button type="submit">{{ env.submit_name }}</button></div>
|
||||
</form>
|
||||
<script>
|
||||
const form = document.getElementById('preauth-form');
|
||||
const message = document.getElementById('preauth-message');
|
||||
|
||||
{% if env.allow_password %}
|
||||
const usePw = document.getElementById('preauth-use-pw');
|
||||
const useTk = document.getElementById('preauth-use-tk');
|
||||
const boxPw = document.querySelectorAll('.boxPw');
|
||||
const boxTk = document.querySelectorAll('.boxTk');
|
||||
|
||||
usePw.addEventListener('click', (event) => {
|
||||
form.preauth_token.value = '';
|
||||
form.preauth_token.disabled = true;
|
||||
form.preauth_password.disabled = false;
|
||||
boxTk.forEach((element) => {
|
||||
element.classList.add('hidden');
|
||||
});
|
||||
boxPw.forEach((element) => {
|
||||
element.classList.remove('hidden');
|
||||
});
|
||||
});
|
||||
|
||||
useTk.addEventListener('click', (event) => {
|
||||
form.preauth_password.value = '';
|
||||
form.preauth_password.disabled = true;
|
||||
form.preauth_token.disabled = false;
|
||||
boxPw.forEach((element) => {
|
||||
element.classList.add('hidden');
|
||||
});
|
||||
boxTk.forEach((element) => {
|
||||
element.classList.remove('hidden');
|
||||
});
|
||||
});
|
||||
{% if not post ?? false %}
|
||||
{{- include('_script.html.twig') -}}
|
||||
{% endif %}
|
||||
|
||||
form.addEventListener('submit', (event) => {
|
||||
event.preventDefault();
|
||||
|
||||
{% if env.allow_password %}
|
||||
/* make base64url string containing our payload json object */
|
||||
/* payload will contain either token or password */
|
||||
const data = btoa(JSON.stringify({
|
||||
id: form.preauth_id.value,
|
||||
...( form.preauth_token.value && { token: form.preauth_token.value }),
|
||||
...(( ! form.preauth_token.value) && { password: form.preauth_password.value }),
|
||||
nonce: form.preauth_nonce.value,
|
||||
json: true
|
||||
})).replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '');
|
||||
{% else %}
|
||||
/* make base64url string containing our payload json object */
|
||||
const data = btoa(JSON.stringify({
|
||||
id: form.preauth_id.value,
|
||||
token: form.preauth_token.value,
|
||||
nonce: form.preauth_nonce.value,
|
||||
json: true
|
||||
})).replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '');
|
||||
{% endif %}
|
||||
|
||||
/* send our request to the server */
|
||||
fetch(window.location.href, {
|
||||
method: 'GET',
|
||||
headers: { 'X-Preauth': data },
|
||||
}).then((response) => {
|
||||
if (response.headers.has('Location')) {
|
||||
/* follow redirect (not needed in most browsers) */
|
||||
window.location.href = response.headers.get('Location');
|
||||
} else if (response.headers.get('Content-Type') === 'application/json') {
|
||||
/* got json, update the page */
|
||||
response.json().then((content) => {
|
||||
if (Object.hasOwn(content, 'message')) {
|
||||
message.innerText = content.message;
|
||||
}
|
||||
if (Object.hasOwn(content, 'nonce')) {
|
||||
form.preauth_nonce.value = content.nonce;
|
||||
form.preauth_token.value = '';
|
||||
form.preauth_token.focus();
|
||||
}
|
||||
}).catch((error) => {
|
||||
console.log('failed to parse json from response');
|
||||
console.log(error);
|
||||
});
|
||||
} else { /* non-json, non-redirect response */
|
||||
/* overwrite the page */
|
||||
response.text().then((text) => {
|
||||
document.open();
|
||||
document.write(text);
|
||||
document.close();
|
||||
}).catch((error) => {
|
||||
console.log('failed to get text from response');
|
||||
console.log(error);
|
||||
});
|
||||
}
|
||||
});
|
||||
});
|
||||
</script>
|
||||
{% endblock %}
|
||||
|
||||
@@ -0,0 +1,514 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Functional;
|
||||
|
||||
use App\Data\Payload;
|
||||
use App\Enum\Scope;
|
||||
use OTPHP\TOTP;
|
||||
use Symfony\Bundle\FrameworkBundle\KernelBrowser;
|
||||
use Symfony\Bundle\FrameworkBundle\Test\WebTestCase;
|
||||
|
||||
/**
|
||||
* End-to-end functional tests exercising the full HTTP kernel: the request
|
||||
* travels through RejectListener -> LoginListener -> AllowListener ->
|
||||
* AcceptListener -> InterceptListener and the services they orchestrate.
|
||||
*/
|
||||
final class AuthenticationFlowTest extends WebTestCase
|
||||
{
|
||||
private const string TOTP_SECRET = 'JBSWY3DPEHPK3PXP';
|
||||
private const string COOKIE_NAME = '__Host-Http-Preauth';
|
||||
|
||||
protected static function createClient(array $options = [], array $server = []): KernelBrowser
|
||||
{
|
||||
$client = parent::createClient($options, $server);
|
||||
// The app stores nonces in the (in-memory) nonceCache pool. In
|
||||
// production APCu keeps them across requests, but KernelBrowser
|
||||
// reboots the kernel between requests by default which would lose
|
||||
// them. Disable the reboot so the nonce issued on the login-page
|
||||
// request survives to the login-submission request.
|
||||
$client->disableReboot();
|
||||
|
||||
return $client;
|
||||
}
|
||||
|
||||
private function validTotpCode(): string
|
||||
{
|
||||
// the app uses the real system clock, so generate the code for now()
|
||||
return TOTP::createFromSecret(self::TOTP_SECRET)->now();
|
||||
}
|
||||
|
||||
/** base64url-encode a payload, matching the client-side JS / X-Preauth header. */
|
||||
private function encodePayload(array $data): string
|
||||
{
|
||||
$json = json_encode($data, JSON_THROW_ON_ERROR);
|
||||
return rtrim(strtr(base64_encode($json), '+/', '-_'), '=');
|
||||
}
|
||||
|
||||
private function loginPayload(
|
||||
string $id = 'testuser',
|
||||
?string $token = null,
|
||||
string $nonce = 'test-nonce-abc',
|
||||
bool $json = true,
|
||||
): string {
|
||||
return $this->encodePayload([
|
||||
'id' => $id,
|
||||
'token' => $token ?? $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'json' => $json,
|
||||
]);
|
||||
}
|
||||
|
||||
/* ── unauthenticated access ──────────────────────────────────────── */
|
||||
|
||||
public function testUnauthenticatedRequestShowsLoginPage(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
$client->request('GET', '/');
|
||||
|
||||
// login page is served with 401 (Unauthorized) to signal the proxy
|
||||
self::assertSame(401, $client->getResponse()->getStatusCode());
|
||||
self::assertSelectorExists('form#preauth-form');
|
||||
self::assertSelectorExists('input[name="nonce"]');
|
||||
self::assertSelectorExists('input[name="username"]');
|
||||
self::assertSelectorExists('input[name="totp"]');
|
||||
}
|
||||
|
||||
public function testLoginPageContainsGeneratedNonce(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
$crawler = $client->request('GET', '/');
|
||||
|
||||
$nonceInput = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
self::assertNotEmpty($nonceInput);
|
||||
// base64url charset
|
||||
self::assertMatchesRegularExpression('/^[A-Za-z0-9_-]+$/', $nonceInput);
|
||||
}
|
||||
|
||||
public function testLoginFormDoesNotUsePostMethodWithoutAuthSubdomain(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
$crawler = $client->request('GET', '/');
|
||||
|
||||
$form = $crawler->filter('form#preauth-form');
|
||||
// without central auth, the form should NOT have method="post"
|
||||
$method = $form->attr('method');
|
||||
self::assertNull($method);
|
||||
}
|
||||
|
||||
/* ── successful TOTP login ────────────────────────────────────────── */
|
||||
|
||||
public function testSuccessfulTotpLoginViaHeaderSetsCookieAndRedirects(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
// first, grab a valid nonce from the login page
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
self::assertNotEmpty($nonce);
|
||||
|
||||
// now submit a valid TOTP via the X-Preauth header
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(303, $response->getStatusCode()); // SEE_OTHER
|
||||
self::assertTrue($response->headers->has('Location'));
|
||||
// a session cookie should be set
|
||||
$cookies = $response->headers->getCookies();
|
||||
$hasPreauthCookie = false;
|
||||
foreach ($cookies as $cookie) {
|
||||
if (str_contains($cookie->getName(), 'Preauth')) {
|
||||
$hasPreauthCookie = true;
|
||||
}
|
||||
}
|
||||
self::assertTrue($hasPreauthCookie, 'Expected a preauth cookie to be set after login');
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginReturnsJsonWhenJsonRequested(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'bob',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(303, $response->getStatusCode());
|
||||
self::assertSame('application/json', $response->headers->get('Content-Type'));
|
||||
$body = json_decode($response->getContent(), true);
|
||||
self::assertSame('Login successful', $body['message']);
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginReturnsHtmlWhenJsonFalse(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'carol',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'json' => false,
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(303, $response->getStatusCode());
|
||||
self::assertStringStartsWith('text/html', $response->headers->get('Content-Type'));
|
||||
}
|
||||
|
||||
public function testAuthenticatedCookieAccessAfterLogin(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
// login
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'dave',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
// grab the cookie value from the login response
|
||||
$loginResponse = $client->getResponse();
|
||||
$cookieValue = null;
|
||||
foreach ($loginResponse->headers->getCookies() as $cookie) {
|
||||
if (str_contains($cookie->getName(), 'Preauth')) {
|
||||
$cookieValue = $cookie->getValue();
|
||||
}
|
||||
}
|
||||
self::assertNotNull($cookieValue);
|
||||
|
||||
// the cookie was set with secure=true, so the CookieJar will only
|
||||
// send it over HTTPS; the KernelBrowser automatically updates the
|
||||
// CookieJar from the login response, so the next request over HTTPS
|
||||
// will include it
|
||||
$client->request('GET', 'https://localhost/dashboard');
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(200, $response->getStatusCode());
|
||||
self::assertSame('dave', $response->headers->get('Remote-User'));
|
||||
}
|
||||
|
||||
public function testScopeNoneReturnsPlainTextWithoutRedirect(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'eve',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'scope' => 'none',
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(200, $response->getStatusCode());
|
||||
self::assertStringStartsWith('text/plain', $response->headers->get('Content-Type'));
|
||||
self::assertSame('eve', $response->headers->get('Remote-User'));
|
||||
// no redirect for scope=none
|
||||
self::assertFalse($response->headers->has('Location'));
|
||||
}
|
||||
|
||||
/* ── failed login ─────────────────────────────────────────────────── */
|
||||
|
||||
public function testFailedLoginReturnsUnauthorizedJsonWithError(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice',
|
||||
'token' => '000000', // wrong code
|
||||
'nonce' => $nonce,
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(401, $response->getStatusCode());
|
||||
self::assertSame('application/json', $response->headers->get('Content-Type'));
|
||||
$body = json_decode($response->getContent(), true);
|
||||
self::assertArrayHasKey('message', $body);
|
||||
self::assertArrayHasKey('nonce', $body);
|
||||
// a fresh nonce should be returned for the next attempt
|
||||
self::assertNotEmpty($body['nonce']);
|
||||
}
|
||||
|
||||
public function testFailedLoginReturnsHtmlWhenJsonFalse(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice',
|
||||
'token' => 'wrong-code',
|
||||
'nonce' => $nonce,
|
||||
'json' => false,
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(401, $response->getStatusCode());
|
||||
self::assertStringStartsWith('text/html', $response->headers->get('Content-Type'));
|
||||
self::assertSelectorExists('form#preauth-form');
|
||||
}
|
||||
|
||||
public function testFailedLoginWithSpentNonceIsRejected(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
// first: successful login consumes the nonce
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
self::assertSame(303, $client->getResponse()->getStatusCode());
|
||||
|
||||
// the successful login set a session cookie; clear it so the next
|
||||
// request is not auto-authenticated by AcceptListener before the
|
||||
// login attempt is even evaluated
|
||||
$client->getCookieJar()->clear();
|
||||
|
||||
// reuse the same nonce — should fail even with a valid token
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce,
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
self::assertSame(401, $client->getResponse()->getStatusCode());
|
||||
}
|
||||
|
||||
public function testFailedLoginWithInvalidNonceIsRejected(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
// skip fetching a real nonce; use one that was never stored
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice',
|
||||
'token' => $this->validTotpCode(),
|
||||
'nonce' => 'never-issued-nonce',
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
self::assertSame(401, $client->getResponse()->getStatusCode());
|
||||
}
|
||||
|
||||
/* ── invalid payload ──────────────────────────────────────────────── */
|
||||
|
||||
public function testInvalidHeaderPayloadReturnsUnauthorized(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => '!!!not-valid-base64!!!',
|
||||
]);
|
||||
|
||||
// decode fails -> null payload -> failure path -> 401
|
||||
self::assertSame(401, $client->getResponse()->getStatusCode());
|
||||
}
|
||||
|
||||
public function testPayloadWithMissingFieldsReturnsUnauthorized(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
// payload missing token
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice', 'nonce' => 'some-nonce',
|
||||
]),
|
||||
]);
|
||||
|
||||
self::assertSame(401, $client->getResponse()->getStatusCode());
|
||||
}
|
||||
|
||||
/* ── invalid cookie ───────────────────────────────────────────────── */
|
||||
|
||||
public function testInvalidCookieIsClearedAndLoginPageShown(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
// the cookie must be set via the CookieJar so that the HttpFoundation
|
||||
// Request actually populates its cookies bag (HTTP_COOKIE alone is
|
||||
// not parsed by Request::create)
|
||||
$client->getCookieJar()->set(
|
||||
new \Symfony\Component\BrowserKit\Cookie(
|
||||
self::COOKIE_NAME,
|
||||
'invalid-ulid-value',
|
||||
null,
|
||||
'/',
|
||||
'localhost',
|
||||
true,
|
||||
true,
|
||||
false,
|
||||
'Strict',
|
||||
)
|
||||
);
|
||||
|
||||
$client->request('GET', 'https://localhost/');
|
||||
|
||||
$response = $client->getResponse();
|
||||
// not authenticated -> login page with 401
|
||||
self::assertSame(401, $response->getStatusCode());
|
||||
// the stale cookie should be cleared
|
||||
$cleared = false;
|
||||
foreach ($response->headers->getCookies() as $cookie) {
|
||||
if ($cookie->getName() === self::COOKIE_NAME && $cookie->isCleared()) {
|
||||
$cleared = true;
|
||||
}
|
||||
}
|
||||
self::assertTrue($cleared, 'Expected the invalid cookie to be cleared');
|
||||
}
|
||||
|
||||
/* ── backup code authentication ───────────────────────────────────── */
|
||||
|
||||
public function testBackupCodeAuthenticationWorks(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
$container = $client->getContainer();
|
||||
|
||||
// generate a backup code via the BackupCodeManager
|
||||
$manager = $container->get(\App\Service\BackupCodeInterface::class);
|
||||
$codes = $manager->generate(1);
|
||||
self::assertCount(1, $codes);
|
||||
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'frank',
|
||||
'token' => $codes[0],
|
||||
'nonce' => $nonce,
|
||||
'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
self::assertSame(303, $client->getResponse()->getStatusCode());
|
||||
}
|
||||
|
||||
public function testConsumedBackupCodeCannotBeReused(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
$container = $client->getContainer();
|
||||
|
||||
$manager = $container->get(\App\Service\BackupCodeInterface::class);
|
||||
$codes = $manager->generate(1);
|
||||
$code = $codes[0];
|
||||
|
||||
// first use
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'frank', 'token' => $code, 'nonce' => $nonce, 'json' => true,
|
||||
]),
|
||||
]);
|
||||
self::assertSame(303, $client->getResponse()->getStatusCode());
|
||||
|
||||
// the successful login set a session cookie; clear it so the next
|
||||
// request reaches the login page instead of being auto-authenticated
|
||||
$client->getCookieJar()->clear();
|
||||
|
||||
// second use with a fresh nonce
|
||||
$crawler = $client->request('GET', '/');
|
||||
$nonce2 = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
$client->request('GET', '/', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'frank', 'token' => $code, 'nonce' => $nonce2, 'json' => true,
|
||||
]),
|
||||
]);
|
||||
self::assertSame(401, $client->getResponse()->getStatusCode());
|
||||
}
|
||||
|
||||
/* ── return URL handling ──────────────────────────────────────────── */
|
||||
|
||||
public function testSuccessfulLoginWithValidReturnUrl(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/?return=https://example.com/app');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/?return=https://example.com/app', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice', 'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce, 'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(303, $response->getStatusCode());
|
||||
self::assertSame('https://example.com/app', $response->headers->get('Location'));
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginWithInvalidReturnFallsBackToPath(): void
|
||||
{
|
||||
$client = static::createClient();
|
||||
|
||||
$crawler = $client->request('GET', '/?return=not-a-url');
|
||||
$nonce = $crawler->filter('input[name="nonce"]')->attr('value');
|
||||
|
||||
$client->request('GET', '/?return=not-a-url', [], [], [
|
||||
'HTTP_X-Preauth' => $this->encodePayload([
|
||||
'id' => 'alice', 'token' => $this->validTotpCode(),
|
||||
'nonce' => $nonce, 'json' => true,
|
||||
]),
|
||||
]);
|
||||
|
||||
$response = $client->getResponse();
|
||||
self::assertSame(303, $response->getStatusCode());
|
||||
$location = $response->headers->get('Location');
|
||||
// should fall back to the request path (with query string),
|
||||
// not redirect to the invalid return URL as an absolute URL
|
||||
self::assertStringStartsWith('/', $location);
|
||||
// the invalid return URL is not used as the redirect target
|
||||
self::assertStringNotContainsString('//not-a-url', $location);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,136 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Support;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Service\DomainManager;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\RateLimiter\RateLimit;
|
||||
use Symfony\Component\RateLimiter\RateLimiterFactoryInterface;
|
||||
use Symfony\Component\RateLimiter\LimiterInterface;
|
||||
use Twig\Environment;
|
||||
use Twig\Loader\FilesystemLoader;
|
||||
|
||||
/**
|
||||
* Helpers for constructing the collaborators that the kernel listeners
|
||||
* depend on, without booting the full Symfony container.
|
||||
*/
|
||||
trait ListenerTestHelper
|
||||
{
|
||||
use TotpTestHelper;
|
||||
|
||||
/** Build a Twig Environment pointed at the project's real templates. */
|
||||
private function makeTwig(): Environment
|
||||
{
|
||||
$loader = new FilesystemLoader(dirname(__DIR__, 2) . '/templates');
|
||||
$twig = new Environment($loader, ['strict_variables' => true]);
|
||||
// the templates reference a global `env` object; supply one with the
|
||||
// keys used by base/login/error/_script/_style
|
||||
$twig->addGlobal('env', (object)[
|
||||
'title' => 'Pre-Authentication System',
|
||||
'bg_color' => '#029386',
|
||||
'fg_color' => '#ffffff',
|
||||
'error_color' => '#ffb16d',
|
||||
'id_name' => 'Session ID',
|
||||
'token_name' => 'Authentication Token',
|
||||
'submit_name' => 'Submit',
|
||||
'error_message' => 'Unsuccessful login attempt',
|
||||
'teapot' => true,
|
||||
'teapot_title' => "I'm a teapot",
|
||||
'teapot_message' => 'I refuse to brew coffee',
|
||||
'too_many_title' => 'Too many requests',
|
||||
'too_many_message' => 'Try again later',
|
||||
'debug' => 0,
|
||||
]);
|
||||
return $twig;
|
||||
}
|
||||
|
||||
/**
|
||||
* A RateLimiterFactoryInterface whose created limiter returns a RateLimit
|
||||
* with the given remaining tokens.
|
||||
*/
|
||||
private function makeRateLimiterFactory(int $remainingTokens): RateLimiterFactoryInterface
|
||||
{
|
||||
$limiter = $this->makeLimiter($remainingTokens);
|
||||
return new class ($limiter) implements RateLimiterFactoryInterface {
|
||||
public function __construct(private LimiterInterface $limiter)
|
||||
{
|
||||
}
|
||||
public function create(?string $key = null): LimiterInterface
|
||||
{
|
||||
return $this->limiter;
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
private function makeLimiter(int $remainingTokens): LimiterInterface
|
||||
{
|
||||
$rateLimit = new RateLimit(
|
||||
$remainingTokens,
|
||||
new \DateTimeImmutable('+10 seconds'),
|
||||
$remainingTokens > 0,
|
||||
10,
|
||||
);
|
||||
return new class ($rateLimit) implements LimiterInterface {
|
||||
public function __construct(private RateLimit $rateLimit)
|
||||
{
|
||||
}
|
||||
public function reserve(int $tokens = 1, ?float $maxTime = null): \Symfony\Component\RateLimiter\Reservation
|
||||
{
|
||||
throw new \Symfony\Component\RateLimiter\Exception\ReserveNotSupportedException();
|
||||
}
|
||||
public function consume(int $tokens = 1): RateLimit
|
||||
{
|
||||
return $this->rateLimit;
|
||||
}
|
||||
public function reset(): void
|
||||
{
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* A factory whose limiter tracks how many consume(1) calls were made and
|
||||
* reports the limit as reached only after $threshold failures.
|
||||
*/
|
||||
private function makeCountingRateLimiterFactory(int $threshold): RateLimiterFactoryInterface
|
||||
{
|
||||
$limiter = new class ($threshold) implements LimiterInterface {
|
||||
private int $consumed = 0;
|
||||
public function __construct(private int $threshold)
|
||||
{
|
||||
}
|
||||
public function reserve(int $tokens = 1, ?float $maxTime = null): \Symfony\Component\RateLimiter\Reservation
|
||||
{
|
||||
throw new \Symfony\Component\RateLimiter\Exception\ReserveNotSupportedException();
|
||||
}
|
||||
public function consume(int $tokens = 1): RateLimit
|
||||
{
|
||||
$this->consumed += $tokens;
|
||||
$remaining = max(0, $this->threshold - $this->consumed);
|
||||
return new RateLimit(
|
||||
$remaining,
|
||||
new \DateTimeImmutable('+10 seconds'),
|
||||
$remaining > 0,
|
||||
$this->threshold,
|
||||
);
|
||||
}
|
||||
public function reset(): void
|
||||
{
|
||||
$this->consumed = 0;
|
||||
}
|
||||
};
|
||||
return new class ($limiter) implements RateLimiterFactoryInterface {
|
||||
public function __construct(private LimiterInterface $limiter)
|
||||
{
|
||||
}
|
||||
public function create(?string $key = null): LimiterInterface
|
||||
{
|
||||
return $this->limiter;
|
||||
}
|
||||
};
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,105 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Support;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Utilities;
|
||||
use DateTimeImmutable;
|
||||
use OTPHP\TOTP;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Cache\CacheItemInterface;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Clock\ClockInterface as PsrClockInterface;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
|
||||
/**
|
||||
* Provides a deterministic TOTP fixture plus a frozen clock and ready-made
|
||||
* ConfigBag / cache-pool helpers for tests that exercise TOTP-dependent code.
|
||||
*/
|
||||
trait TotpTestHelper
|
||||
{
|
||||
/** well-known Base32 test secret (JBSWY3DPEHPK3PXP) */
|
||||
private const string TOTP_SECRET = 'JBSWY3DPEHPK3PXP';
|
||||
|
||||
/** Frozen timestamp used for deterministic TOTP codes. */
|
||||
protected const string FROZEN_TIME = '2025-06-15 12:00:00';
|
||||
|
||||
/** Frozen clock that always returns the same instant. */
|
||||
private function frozenClock(): PsrClockInterface
|
||||
{
|
||||
$time = self::FROZEN_TIME;
|
||||
return new class ($time) implements PsrClockInterface {
|
||||
public function __construct(private string $time)
|
||||
{
|
||||
}
|
||||
public function now(): DateTimeImmutable
|
||||
{
|
||||
return new DateTimeImmutable($this->time);
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
/** Provisioning URI built from the well-known secret + frozen clock. */
|
||||
private function totpUri(): string
|
||||
{
|
||||
$totp = TOTP::createFromSecret(self::TOTP_SECRET, $this->frozenClock());
|
||||
$totp->setLabel('Test-TOTP');
|
||||
return $totp->getProvisioningUri();
|
||||
}
|
||||
|
||||
/** The TOTP code that is valid at the frozen timestamp. */
|
||||
private function validTotpCode(): string
|
||||
{
|
||||
return TOTP::createFromSecret(self::TOTP_SECRET, $this->frozenClock())->now();
|
||||
}
|
||||
|
||||
/** A fresh in-memory cache pool suitable for wrapping in MonitorCacheKeys. */
|
||||
private function emptyPool(): CacheItemPoolInterface
|
||||
{
|
||||
return new ArrayAdapter();
|
||||
}
|
||||
|
||||
/**
|
||||
* Build a ConfigBag wired with the deterministic TOTP and frozen clock.
|
||||
* Extra params override the sensible defaults.
|
||||
*/
|
||||
private function makeConfig(
|
||||
?int $cookieTtl = 3600,
|
||||
?int $ipTtl = 0,
|
||||
bool $teapot = true,
|
||||
string $errorMessage = 'Error',
|
||||
string $teapotTitle = 'Teapot',
|
||||
string $tooManyTitle = 'Too Many',
|
||||
): ConfigBag {
|
||||
$clock = $this->frozenClock();
|
||||
$utilities = $this->createUtilities($clock);
|
||||
return new ConfigBag(
|
||||
$utilities,
|
||||
$clock,
|
||||
$cookieTtl,
|
||||
$this->totpUri(),
|
||||
$ipTtl,
|
||||
$teapot,
|
||||
$errorMessage,
|
||||
$teapotTitle,
|
||||
$tooManyTitle,
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Minimal Utilities stub that never triggers TOTP generation when
|
||||
* a non-empty totpUri is supplied to ConfigBag.
|
||||
*/
|
||||
private function createUtilities(?PsrClockInterface $clock = null): Utilities
|
||||
{
|
||||
$clock ??= $this->frozenClock();
|
||||
$cache = $this->createStub(CacheItemPoolInterface::class);
|
||||
$cache->method('hasItem')->willReturn(false);
|
||||
$item = $this->createStub(CacheItemInterface::class);
|
||||
$item->method('isHit')->willReturn(false);
|
||||
$cache->method('getItem')->willReturn($item);
|
||||
return new Utilities($clock, $cache);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests;
|
||||
|
||||
use App\Kernel as AppKernel;
|
||||
use Symfony\Component\DependencyInjection\Compiler\CompilerPassInterface;
|
||||
use Symfony\Component\DependencyInjection\ContainerBuilder;
|
||||
|
||||
/**
|
||||
* Kernel used by the functional test suite.
|
||||
*
|
||||
* In production the nonce cache is backed by APCu, which naturally persists
|
||||
* across PHP requests. In the test environment the nonce cache is an
|
||||
* in-memory ArrayAdapter; Symfony's ServicesResetter clears it between
|
||||
* requests (even with KernelBrowser::disableReboot()), which would discard
|
||||
* the nonce issued on the login-page request before the login-submission
|
||||
* request can verify it.
|
||||
*
|
||||
* This kernel removes the kernel.reset tag from the nonceCache (and
|
||||
* rateLimitCache) pools so their in-memory state survives across requests
|
||||
* within a single test, mirroring the persistence behaviour of APCu.
|
||||
*/
|
||||
class TestKernel extends AppKernel
|
||||
{
|
||||
protected function build(ContainerBuilder $container): void
|
||||
{
|
||||
parent::build($container);
|
||||
|
||||
$container->addCompilerPass(new class () implements CompilerPassInterface {
|
||||
public function process(ContainerBuilder $container): void
|
||||
{
|
||||
foreach (['nonceCache', 'rateLimitCache', 'sessionCache', 'sessionStorage'] as $poolId) {
|
||||
if ($container->hasDefinition($poolId)) {
|
||||
$container->getDefinition($poolId)->clearTag('kernel.reset');
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit;
|
||||
|
||||
use App\Clock;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
|
||||
final class ClockTest extends TestCase
|
||||
{
|
||||
public function testNowReturnsDateTimeImmutable(): void
|
||||
{
|
||||
$clock = new Clock();
|
||||
$before = new \DateTimeImmutable();
|
||||
$now = $clock->now();
|
||||
$after = new \DateTimeImmutable();
|
||||
|
||||
self::assertInstanceOf(\DateTimeImmutable::class, $now);
|
||||
self::assertGreaterThanOrEqual($before->getTimestamp(), $now->getTimestamp());
|
||||
self::assertLessThanOrEqual($after->getTimestamp(), $now->getTimestamp());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,133 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Command;
|
||||
|
||||
use App\Command\GenerateBackupCodesCommand;
|
||||
use App\PersistCache;
|
||||
use App\Service\BackupCodeInterface;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\Console\Tester\CommandTester;
|
||||
|
||||
final class GenerateBackupCodesCommandTest extends TestCase
|
||||
{
|
||||
/** PersistCache is final, so construct a real one backed by ArrayAdapters. */
|
||||
private function makePersistCache(): PersistCache
|
||||
{
|
||||
return new PersistCache(new ArrayAdapter(), new ArrayAdapter());
|
||||
}
|
||||
|
||||
/** A stub BackupCodeInterface that returns the given codes from generate(). */
|
||||
private function makeManagerStub(array $generatedCodes): BackupCodeInterface
|
||||
{
|
||||
$manager = $this->createStub(BackupCodeInterface::class);
|
||||
$manager->method('generate')->willReturn($generatedCodes);
|
||||
return $manager;
|
||||
}
|
||||
|
||||
public function testGenerateDefaultCountOutputsCodes(): void
|
||||
{
|
||||
$codes = ['abc123', 'def456', 'ghi789', 'jkl012', 'mno345',
|
||||
'pqr678', 'stu901', 'vwx234', 'yzA567', 'bCd890'];
|
||||
$command = new GenerateBackupCodesCommand(
|
||||
$this->makeManagerStub($codes),
|
||||
$this->makePersistCache()
|
||||
);
|
||||
$command->setName('app:generate-backup-codes');
|
||||
|
||||
$tester = new CommandTester($command);
|
||||
$exit = $tester->execute([]);
|
||||
|
||||
self::assertSame(0, $exit);
|
||||
$output = $tester->getDisplay();
|
||||
foreach ($codes as $code) {
|
||||
self::assertStringContainsString($code, $output);
|
||||
}
|
||||
}
|
||||
|
||||
public function testGenerateSpecificCountPassesCountToManager(): void
|
||||
{
|
||||
$manager = $this->createMock(BackupCodeInterface::class);
|
||||
$manager->expects(self::once())
|
||||
->method('generate')
|
||||
->with(self::identicalTo(5))
|
||||
->willReturn(['c1', 'c2', 'c3', 'c4', 'c5']);
|
||||
|
||||
$command = new GenerateBackupCodesCommand($manager, $this->makePersistCache());
|
||||
$command->setName('app:generate-backup-codes');
|
||||
|
||||
$tester = new CommandTester($command);
|
||||
$exit = $tester->execute(['count' => 5]);
|
||||
|
||||
self::assertSame(0, $exit);
|
||||
}
|
||||
|
||||
public function testDefaultCountArgumentIsTen(): void
|
||||
{
|
||||
// the configured default for the count argument should be 10
|
||||
$manager = $this->createMock(BackupCodeInterface::class);
|
||||
$manager->expects(self::once())
|
||||
->method('generate')
|
||||
->with(self::identicalTo(10))
|
||||
->willReturn(array_fill(0, 10, 'code'));
|
||||
|
||||
$command = new GenerateBackupCodesCommand($manager, $this->makePersistCache());
|
||||
$command->setName('app:generate-backup-codes');
|
||||
|
||||
$tester = new CommandTester($command);
|
||||
$tester->execute([]);
|
||||
|
||||
// assertion is in the mock expectation above
|
||||
$this->addToAssertionCount(1);
|
||||
}
|
||||
|
||||
public function testBootsAndPersistsCache(): void
|
||||
{
|
||||
// PersistCache is final and can't be mocked, but we can verify the
|
||||
// command runs end-to-end with a real instance; boot()/persist()
|
||||
// are invoked implicitly. A successful exit confirms both were called
|
||||
// without throwing.
|
||||
$command = new GenerateBackupCodesCommand(
|
||||
$this->makeManagerStub(['code1']),
|
||||
$this->makePersistCache()
|
||||
);
|
||||
$command->setName('app:generate-backup-codes');
|
||||
|
||||
$tester = new CommandTester($command);
|
||||
$exit = $tester->execute([]);
|
||||
|
||||
self::assertSame(0, $exit);
|
||||
}
|
||||
|
||||
public function testZeroCodesOutputsNothing(): void
|
||||
{
|
||||
$command = new GenerateBackupCodesCommand(
|
||||
$this->makeManagerStub([]),
|
||||
$this->makePersistCache()
|
||||
);
|
||||
$command->setName('app:generate-backup-codes');
|
||||
|
||||
$tester = new CommandTester($command);
|
||||
$exit = $tester->execute(['count' => 0]);
|
||||
|
||||
self::assertSame(0, $exit);
|
||||
self::assertSame('', trim($tester->getDisplay()));
|
||||
}
|
||||
|
||||
public function testCommandNameAndDescriptionAreConfigured(): void
|
||||
{
|
||||
$command = new GenerateBackupCodesCommand(
|
||||
$this->makeManagerStub([]),
|
||||
$this->makePersistCache()
|
||||
);
|
||||
// configuring via the Application runs the protected configure()
|
||||
$app = new \Symfony\Component\Console\Application();
|
||||
$app->addCommand($command);
|
||||
self::assertSame('app:generate-backup-codes', $command->getName());
|
||||
// the source uses a non-breaking hyphen (U+2011) in "single‑use",
|
||||
// so assert against the substring to avoid encoding fragility
|
||||
self::assertStringContainsString('backup codes', $command->getDescription());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,120 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Utilities;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Cache\CacheItemInterface;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Clock\ClockInterface;
|
||||
|
||||
final class ConfigBagTest extends TestCase
|
||||
{
|
||||
private function createUtilities(?string $totp = null): Utilities
|
||||
{
|
||||
$clock = $this->createStub(ClockInterface::class);
|
||||
$cache = $this->createStub(CacheItemPoolInterface::class);
|
||||
|
||||
if ($totp !== null) {
|
||||
$item = $this->createStub(CacheItemInterface::class);
|
||||
$item->method('isHit')->willReturn(true);
|
||||
$item->method('get')->willReturn($totp);
|
||||
$cache->method('hasItem')->willReturn(true);
|
||||
$cache->method('getItem')->willReturn($item);
|
||||
} else {
|
||||
$cache->method('hasItem')->willReturn(false);
|
||||
}
|
||||
|
||||
return new Utilities($clock, $cache);
|
||||
}
|
||||
|
||||
public function testGettersWithExplicitValues(): void
|
||||
{
|
||||
$clock = $this->createStub(ClockInterface::class);
|
||||
$utilities = $this->createUtilities();
|
||||
|
||||
$config = new ConfigBag(
|
||||
$utilities,
|
||||
$clock,
|
||||
3600,
|
||||
'otpauth://totp/test',
|
||||
1800,
|
||||
true,
|
||||
'Error!',
|
||||
'Teapot!',
|
||||
'Too Many!'
|
||||
);
|
||||
|
||||
self::assertSame($clock, $config->clock());
|
||||
self::assertSame(3600, $config->cookieTtl());
|
||||
self::assertSame('otpauth://totp/test', $config->totpUri());
|
||||
self::assertSame(1800, $config->ipTtl());
|
||||
self::assertTrue($config->teapot());
|
||||
self::assertSame('Error!', $config->errorMessage());
|
||||
self::assertSame('Teapot!', $config->teapotTitle());
|
||||
self::assertSame('Too Many!', $config->tooManyTitle());
|
||||
}
|
||||
|
||||
public function testTotpUriFallsBackToUtilitiesWhenEmpty(): void
|
||||
{
|
||||
$clock = $this->createStub(ClockInterface::class);
|
||||
$utilities = $this->createUtilities('fallback-totp');
|
||||
|
||||
$config = new ConfigBag(
|
||||
$utilities,
|
||||
$clock,
|
||||
3600,
|
||||
'',
|
||||
1800,
|
||||
false,
|
||||
'Error',
|
||||
'Teapot',
|
||||
'Too Many'
|
||||
);
|
||||
|
||||
self::assertSame('fallback-totp', $config->totpUri());
|
||||
}
|
||||
|
||||
public function testIpTtlFallsBackToNullWhenZero(): void
|
||||
{
|
||||
$clock = $this->createStub(ClockInterface::class);
|
||||
$utilities = $this->createUtilities();
|
||||
|
||||
$config = new ConfigBag(
|
||||
$utilities,
|
||||
$clock,
|
||||
3600,
|
||||
'otpauth://totp/test',
|
||||
0,
|
||||
false,
|
||||
'Error',
|
||||
'Teapot',
|
||||
'Too Many'
|
||||
);
|
||||
|
||||
self::assertNull($config->ipTtl());
|
||||
}
|
||||
|
||||
public function testIpTtlFallsBackToNullWhenNull(): void
|
||||
{
|
||||
$clock = $this->createStub(ClockInterface::class);
|
||||
$utilities = $this->createUtilities();
|
||||
|
||||
$config = new ConfigBag(
|
||||
$utilities,
|
||||
$clock,
|
||||
3600,
|
||||
'otpauth://totp/test',
|
||||
null,
|
||||
false,
|
||||
'Error',
|
||||
'Teapot',
|
||||
'Too Many'
|
||||
);
|
||||
|
||||
self::assertNull($config->ipTtl());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,223 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Data;
|
||||
|
||||
use App\Data\Payload;
|
||||
use App\Enum\Scope;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Symfony\Component\HttpFoundation\InputBag;
|
||||
|
||||
final class PayloadTest extends TestCase
|
||||
{
|
||||
private static function b64u(string $data): string
|
||||
{
|
||||
return rtrim(strtr(base64_encode($data), '+/', '-_'), '=');
|
||||
}
|
||||
|
||||
public function testDecodeValidBase64Url(): void
|
||||
{
|
||||
$data = json_encode([
|
||||
'id' => 'testuser', 'token' => '123456', 'nonce' => 'abc123',
|
||||
'json' => true, 'scope' => 'cookie',
|
||||
]);
|
||||
$payload = Payload::decode(self::b64u($data));
|
||||
|
||||
self::assertInstanceOf(Payload::class, $payload);
|
||||
self::assertSame('testuser', $payload->id);
|
||||
self::assertSame('123456', $payload->token);
|
||||
self::assertSame('abc123', $payload->nonce);
|
||||
self::assertTrue($payload->json);
|
||||
self::assertSame(Scope::Cookie, $payload->scope);
|
||||
}
|
||||
|
||||
public function testDecodeInvalidBase64UrlReturnsNull(): void
|
||||
{
|
||||
self::assertNull(Payload::decode('!!!not-valid-base64!!!'));
|
||||
}
|
||||
|
||||
public function testDecodeNonObjectJsonReturnsNull(): void
|
||||
{
|
||||
self::assertNull(Payload::decode(self::b64u('"just a string"')));
|
||||
}
|
||||
|
||||
public function testDecodeInvalidJsonReturnsNull(): void
|
||||
{
|
||||
// valid base64url but invalid JSON
|
||||
self::assertNull(Payload::decode(self::b64u('{invalid json')));
|
||||
}
|
||||
|
||||
public function testDecodeJsonArrayReturnsNull(): void
|
||||
{
|
||||
self::assertNull(Payload::decode(self::b64u('[1,2,3]')));
|
||||
}
|
||||
|
||||
public function testDecodeJsonNullReturnsNull(): void
|
||||
{
|
||||
self::assertNull(Payload::decode(self::b64u('null')));
|
||||
}
|
||||
|
||||
public function testDecodeJsonBooleanReturnsNull(): void
|
||||
{
|
||||
self::assertNull(Payload::decode(self::b64u('true')));
|
||||
self::assertNull(Payload::decode(self::b64u('false')));
|
||||
}
|
||||
|
||||
public function testDecodeJsonNumberReturnsNull(): void
|
||||
{
|
||||
self::assertNull(Payload::decode(self::b64u('42')));
|
||||
}
|
||||
|
||||
public function testDecodeEmptyStringReturnsNull(): void
|
||||
{
|
||||
self::assertNull(Payload::decode(''));
|
||||
}
|
||||
|
||||
public function testLoadWithValidInputBag(): void
|
||||
{
|
||||
$input = new InputBag([
|
||||
'username' => 'alice', 'nonce' => 'nonce123', 'totp' => '654321',
|
||||
]);
|
||||
$payload = Payload::load($input);
|
||||
|
||||
self::assertInstanceOf(Payload::class, $payload);
|
||||
self::assertSame('alice', $payload->id);
|
||||
self::assertSame('nonce123', $payload->nonce);
|
||||
self::assertSame('654321', $payload->token);
|
||||
self::assertFalse($payload->json);
|
||||
self::assertSame(Scope::Cookie, $payload->scope);
|
||||
}
|
||||
|
||||
public function testLoadMissingUsernameReturnsNull(): void
|
||||
{
|
||||
$input = new InputBag(['nonce' => 'n', 'totp' => 't']);
|
||||
self::assertNull(Payload::load($input));
|
||||
}
|
||||
|
||||
public function testLoadMissingNonceReturnsNull(): void
|
||||
{
|
||||
$input = new InputBag(['username' => 'u', 'totp' => 't']);
|
||||
self::assertNull(Payload::load($input));
|
||||
}
|
||||
|
||||
public function testLoadMissingTotpReturnsNull(): void
|
||||
{
|
||||
$input = new InputBag(['username' => 'u', 'nonce' => 'n']);
|
||||
self::assertNull(Payload::load($input));
|
||||
}
|
||||
|
||||
public function testLoadWithAllFieldsPresentButEmptyReturnsNull(): void
|
||||
{
|
||||
// has() returns true for all, but create() rejects empty values
|
||||
$input = new InputBag(['username' => '', 'nonce' => '', 'totp' => '']);
|
||||
self::assertNull(Payload::load($input));
|
||||
}
|
||||
|
||||
public function testCreateWithValidData(): void
|
||||
{
|
||||
$data = (object)[
|
||||
'id' => 'user1', 'token' => 'tok1', 'nonce' => 'non1',
|
||||
'json' => false, 'scope' => 'ip',
|
||||
];
|
||||
$payload = Payload::create($data);
|
||||
|
||||
self::assertInstanceOf(Payload::class, $payload);
|
||||
self::assertSame('user1', $payload->id);
|
||||
self::assertSame('tok1', $payload->token);
|
||||
self::assertSame('non1', $payload->nonce);
|
||||
self::assertFalse($payload->json);
|
||||
self::assertSame(Scope::Ip, $payload->scope);
|
||||
}
|
||||
|
||||
public function testCreateWithDefaultScope(): void
|
||||
{
|
||||
$data = (object)['id' => 'user1', 'token' => 'tok1', 'nonce' => 'non1'];
|
||||
$payload = Payload::create($data);
|
||||
self::assertSame(Scope::Cookie, $payload->scope);
|
||||
}
|
||||
|
||||
public function testCreateWithInvalidScopeFallsBackToCookie(): void
|
||||
{
|
||||
$data = (object)[
|
||||
'id' => 'user1', 'token' => 'tok1', 'nonce' => 'non1',
|
||||
'scope' => 'admin',
|
||||
];
|
||||
$payload = Payload::create($data);
|
||||
self::assertSame(Scope::Cookie, $payload->scope);
|
||||
}
|
||||
|
||||
public function testCreateWithMissingJsonDefaultsToTrue(): void
|
||||
{
|
||||
$data = (object)['id' => 'user1', 'token' => 'tok1', 'nonce' => 'non1'];
|
||||
$payload = Payload::create($data);
|
||||
self::assertTrue($payload->json);
|
||||
}
|
||||
|
||||
public function testCreateWithNoneScopeSetsJsonFalse(): void
|
||||
{
|
||||
$data = (object)[
|
||||
'id' => 'user1', 'token' => 'tok1', 'nonce' => 'non1',
|
||||
'json' => true, 'scope' => 'none',
|
||||
];
|
||||
$payload = Payload::create($data);
|
||||
self::assertSame(Scope::None, $payload->scope);
|
||||
self::assertFalse($payload->json);
|
||||
}
|
||||
|
||||
public function testCreateWithEmptyIdReturnsNull(): void
|
||||
{
|
||||
$data = (object)['id' => '', 'token' => 't', 'nonce' => 'n'];
|
||||
self::assertNull(Payload::create($data));
|
||||
}
|
||||
|
||||
public function testCreateWithWhitespaceIdReturnsNull(): void
|
||||
{
|
||||
$data = (object)['id' => ' ', 'token' => 't', 'nonce' => 'n'];
|
||||
self::assertNull(Payload::create($data));
|
||||
}
|
||||
|
||||
public function testCreateWithEmptyTokenReturnsNull(): void
|
||||
{
|
||||
$data = (object)['id' => 'u', 'token' => '', 'nonce' => 'n'];
|
||||
self::assertNull(Payload::create($data));
|
||||
}
|
||||
|
||||
public function testCreateWithEmptyNonceReturnsNull(): void
|
||||
{
|
||||
$data = (object)['id' => 'u', 'token' => 't', 'nonce' => ''];
|
||||
self::assertNull(Payload::create($data));
|
||||
}
|
||||
|
||||
public function testCreateTrimsAndTruncatesFields(): void
|
||||
{
|
||||
$long = str_repeat('a', 200);
|
||||
$data = (object)[
|
||||
'id' => ' ' . $long . ' ',
|
||||
'token' => ' ' . $long . ' ',
|
||||
'nonce' => ' ' . $long . ' ',
|
||||
];
|
||||
$payload = Payload::create($data);
|
||||
$expected = mb_substr($long, 0, 128);
|
||||
self::assertSame($expected, $payload->id);
|
||||
self::assertSame($expected, $payload->token);
|
||||
self::assertSame($expected, $payload->nonce);
|
||||
}
|
||||
|
||||
public function testToString(): void
|
||||
{
|
||||
$payload = new Payload();
|
||||
$payload->id = 'u';
|
||||
$payload->token = 't';
|
||||
$payload->nonce = 'n';
|
||||
$payload->json = true;
|
||||
$payload->scope = Scope::Cookie;
|
||||
|
||||
$decoded = json_decode($payload->toString(), true);
|
||||
self::assertSame('u', $decoded['id']);
|
||||
self::assertSame('t', $decoded['token']);
|
||||
self::assertSame('n', $decoded['nonce']);
|
||||
self::assertTrue($decoded['json']);
|
||||
self::assertSame('cookie', $decoded['scope']);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Enum;
|
||||
|
||||
use App\Enum\Scope;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
|
||||
final class ScopeTest extends TestCase
|
||||
{
|
||||
public function testCases(): void
|
||||
{
|
||||
self::assertSame('cookie', Scope::Cookie->value);
|
||||
self::assertSame('ip', Scope::Ip->value);
|
||||
self::assertSame('none', Scope::None->value);
|
||||
}
|
||||
|
||||
public function testTryFromValid(): void
|
||||
{
|
||||
self::assertSame(Scope::Cookie, Scope::tryFrom('cookie'));
|
||||
self::assertSame(Scope::Ip, Scope::tryFrom('ip'));
|
||||
self::assertSame(Scope::None, Scope::tryFrom('none'));
|
||||
}
|
||||
|
||||
public function testTryFromInvalid(): void
|
||||
{
|
||||
self::assertNull(Scope::tryFrom('invalid'));
|
||||
self::assertNull(Scope::tryFrom(''));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,133 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Listener;
|
||||
|
||||
use App\Listener\AcceptListener;
|
||||
use App\Service\DomainManager;
|
||||
use App\Tests\Support\TotpTestHelper;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Symfony\Component\HttpKernel\HttpKernelInterface;
|
||||
|
||||
final class AcceptListenerTest extends TestCase
|
||||
{
|
||||
use TotpTestHelper;
|
||||
|
||||
private const string COOKIE_NAME = '__Host-Http-Preauth';
|
||||
private const string AUTH_COOKIE_NAME = '__Http-Domain-Preauth';
|
||||
|
||||
private function makeListener(ArrayAdapter $pool, DomainManager $domainManager): AcceptListener
|
||||
{
|
||||
$listener = new AcceptListener($pool, $domainManager);
|
||||
$listener->setLogger(new NullLogger());
|
||||
return $listener;
|
||||
}
|
||||
|
||||
private function makeEvent(Request $request): RequestEvent
|
||||
{
|
||||
return new RequestEvent(
|
||||
$this->createStub(\Symfony\Component\HttpKernel\HttpKernelInterface::class),
|
||||
$request,
|
||||
HttpKernelInterface::MAIN_REQUEST,
|
||||
);
|
||||
}
|
||||
|
||||
/* ── valid cookie session ─────────────────────────────────────────── */
|
||||
|
||||
public function testValidCookieSetsResponseWithRemoteUser(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$ulid = '01HXY1234567890ABCDEFGHIJK';
|
||||
$item = $pool->getItem('cookie_' . $ulid);
|
||||
$item->set('alice');
|
||||
$pool->save($item);
|
||||
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($pool, $domainManager);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
$request->cookies->set(self::COOKIE_NAME, $ulid);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(200, $response->getStatusCode());
|
||||
self::assertSame('alice', $response->headers->get('Remote-User'));
|
||||
self::assertSame('text/plain', $response->headers->get('Content-Type'));
|
||||
}
|
||||
|
||||
public function testValidCookieUsesAuthCookieNameWhenUsingCentralAuth(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$ulid = '01HXY1234567890ABCDEFGHIJK';
|
||||
$item = $pool->getItem('cookie_' . $ulid);
|
||||
$item->set('bob');
|
||||
$pool->save($item);
|
||||
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener($pool, $domainManager);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
$request->cookies->set(self::AUTH_COOKIE_NAME, $ulid);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
self::assertSame('bob', $event->getResponse()->headers->get('Remote-User'));
|
||||
}
|
||||
|
||||
/* ── negative cases ───────────────────────────────────────────────── */
|
||||
|
||||
public function testNoCookieSetsNoResponse(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($pool, $domainManager);
|
||||
|
||||
$event = $this->makeEvent(Request::create('/', 'GET'));
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
|
||||
public function testCookieWithoutSessionSetsNoResponse(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($pool, $domainManager);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
$request->cookies->set(self::COOKIE_NAME, 'unknown-ulid');
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
|
||||
public function testEmptyCookieValueSetsNoResponse(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($pool, $domainManager);
|
||||
|
||||
// cookies->set with empty string
|
||||
$request = Request::create('/', 'GET');
|
||||
$request->cookies->set(self::COOKIE_NAME, '');
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
// empty cookie value should not be treated as a valid session
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,103 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Listener;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Listener\AllowListener;
|
||||
use App\Tests\Support\TotpTestHelper;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Symfony\Component\HttpKernel\HttpKernelInterface;
|
||||
|
||||
final class AllowListenerTest extends TestCase
|
||||
{
|
||||
use TotpTestHelper;
|
||||
|
||||
private function makeListener(ArrayAdapter $pool, ConfigBag $config): AllowListener
|
||||
{
|
||||
$listener = new AllowListener($pool, $config);
|
||||
$listener->setLogger(new NullLogger());
|
||||
return $listener;
|
||||
}
|
||||
|
||||
private function makeEvent(Request $request): RequestEvent
|
||||
{
|
||||
return new RequestEvent(
|
||||
$this->createStub(HttpKernelInterface::class),
|
||||
$request,
|
||||
HttpKernelInterface::MAIN_REQUEST,
|
||||
);
|
||||
}
|
||||
|
||||
public function testValidIpSessionSetsResponseWithRemoteUser(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$item = $pool->getItem('ip_1.2.3.4');
|
||||
$item->set('carol');
|
||||
$pool->save($item);
|
||||
|
||||
$config = $this->makeConfig(ipTtl: 1800);
|
||||
$listener = $this->makeListener($pool, $config);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(200, $response->getStatusCode());
|
||||
self::assertSame('carol', $response->headers->get('Remote-User'));
|
||||
self::assertSame('text/plain', $response->headers->get('Content-Type'));
|
||||
}
|
||||
|
||||
public function testNoIpSessionSetsNoResponse(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$config = $this->makeConfig(ipTtl: 1800);
|
||||
$listener = $this->makeListener($pool, $config);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '9.9.9.9']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
|
||||
public function testIpAccessDisabledSetsNoResponse(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
// even though there's a stored session, ip access is disabled
|
||||
$item = $pool->getItem('ip_1.2.3.4');
|
||||
$item->set('carol');
|
||||
$pool->save($item);
|
||||
|
||||
$config = $this->makeConfig(ipTtl: 0);
|
||||
$listener = $this->makeListener($pool, $config);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
|
||||
public function testIpAccessDisabledDoesNotCheckCache(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$config = $this->makeConfig(ipTtl: 0);
|
||||
$listener = $this->makeListener($pool, $config);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
// when disabled, nothing should have been written/read as a session
|
||||
self::assertFalse($event->hasResponse());
|
||||
self::assertFalse($pool->hasItem('ip_1.2.3.4'));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,218 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Listener;
|
||||
|
||||
use App\Listener\InterceptListener;
|
||||
use App\Service\DomainManager;
|
||||
use App\Tests\Support\ListenerTestHelper;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\HttpFoundation\Cookie;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Symfony\Component\HttpKernel\HttpKernelInterface;
|
||||
|
||||
final class InterceptListenerTest extends TestCase
|
||||
{
|
||||
use ListenerTestHelper;
|
||||
|
||||
private const string COOKIE_NAME = '__Host-Http-Preauth';
|
||||
private const string AUTH_COOKIE_NAME = '__Http-Domain-Preauth';
|
||||
|
||||
private function makeListener(
|
||||
DomainManager $domainManager,
|
||||
?CacheItemPoolInterface $nonceCache = null,
|
||||
): InterceptListener {
|
||||
$listener = new InterceptListener(
|
||||
$this->makeConfig(),
|
||||
$domainManager,
|
||||
$this->makeTwig(),
|
||||
);
|
||||
$listener->setLogger(new NullLogger());
|
||||
$listener->setNonceCache($nonceCache ?? new ArrayAdapter());
|
||||
return $listener;
|
||||
}
|
||||
|
||||
private function makeEvent(Request $request): RequestEvent
|
||||
{
|
||||
return new RequestEvent(
|
||||
$this->createStub(HttpKernelInterface::class),
|
||||
$request,
|
||||
HttpKernelInterface::MAIN_REQUEST,
|
||||
);
|
||||
}
|
||||
|
||||
/* ── central-auth redirect branch ─────────────────────────────────── */
|
||||
|
||||
public function testRedirectsToAuthSubdomainWhenHostMatchesBaseDomain(): void
|
||||
{
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
$request = Request::create('https://app.example.com/dashboard', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_SEE_OTHER, $response->getStatusCode());
|
||||
$location = $response->headers->get('Location');
|
||||
self::assertStringStartsWith('https://auth.example.com/?', $location);
|
||||
// the return query should contain the original url
|
||||
self::assertStringContainsString('return=', $location);
|
||||
self::assertStringContainsString(urlencode('https://app.example.com/dashboard'), $location);
|
||||
}
|
||||
|
||||
public function testDoesNotRedirectWhenAlreadyOnAuthSubdomain(): void
|
||||
{
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
$request = Request::create('https://auth.example.com/', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
// should render login page, not redirect
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertNotSame(Response::HTTP_SEE_OTHER, $response->getStatusCode());
|
||||
self::assertSame(Response::HTTP_UNAUTHORIZED, $response->getStatusCode());
|
||||
}
|
||||
|
||||
/* ── login page rendering branch ──────────────────────────────────── */
|
||||
|
||||
public function testPresentsLoginPageWithUnauthorizedStatus(): void
|
||||
{
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_UNAUTHORIZED, $response->getStatusCode());
|
||||
self::assertSame('text/html', $response->headers->get('Content-Type'));
|
||||
$content = $response->getContent();
|
||||
self::assertStringContainsString('<form', $content);
|
||||
// the rendered page should embed a freshly generated nonce
|
||||
self::assertStringContainsString('name="nonce"', $content);
|
||||
}
|
||||
|
||||
public function testGeneratedNonceIsStoredInCache(): void
|
||||
{
|
||||
$nonceCache = new ArrayAdapter();
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($domainManager, $nonceCache);
|
||||
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
// exactly one nonce should now exist in the cache, marked valid
|
||||
$found = false;
|
||||
foreach ($nonceCache->getValues() as $key => $value) {
|
||||
if (str_starts_with($key, 'test_') || preg_match('/^[A-Za-z0-9_.]+$/', $key)) {
|
||||
$found = true;
|
||||
}
|
||||
}
|
||||
// ArrayAdapter stores raw values; verify at least one item was saved
|
||||
self::assertTrue(count($nonceCache->getValues()) > 0);
|
||||
}
|
||||
|
||||
public function testLoginTemplateUsesPostFormWhenOnAuthSubdomain(): void
|
||||
{
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
$request = Request::create('https://auth.example.com/', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$content = $event->getResponse()->getContent();
|
||||
// when on the auth subdomain, post=true so the form has method="post"
|
||||
self::assertStringContainsString('method="post"', $content);
|
||||
}
|
||||
|
||||
public function testLoginTemplateDoesNotUsePostFormWhenNotOnAuthSubdomain(): void
|
||||
{
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$content = $event->getResponse()->getContent();
|
||||
// not on auth subdomain, so the form should NOT have method="post"
|
||||
self::assertStringNotContainsString('method="post"', $content);
|
||||
}
|
||||
|
||||
/* ── invalid cookie pruning ───────────────────────────────────────── */
|
||||
|
||||
public function testInvalidCookieIsClearedWhenPresent(): void
|
||||
{
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
// send a cookie that won't match any session (so AcceptListener didn't fire)
|
||||
$request->cookies->set(self::COOKIE_NAME, 'stale-ulid');
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
// a Clear-Site-Data style clearCookie should produce a Set-Cookie that expires it
|
||||
$cookies = $response->headers->getCookies();
|
||||
$cleared = false;
|
||||
foreach ($cookies as $cookie) {
|
||||
if ($cookie->getName() === self::COOKIE_NAME && $cookie->isCleared()) {
|
||||
$cleared = true;
|
||||
}
|
||||
}
|
||||
self::assertTrue($cleared, 'Expected the invalid cookie to be cleared');
|
||||
}
|
||||
|
||||
public function testNoCookieClearingWhenNoCookiePresent(): void
|
||||
{
|
||||
$domainManager = new DomainManager(false, '');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$response = $event->getResponse();
|
||||
self::assertSame([], $response->headers->getCookies());
|
||||
}
|
||||
|
||||
public function testInvalidCookieUsesAuthCookieNameWithCentralAuth(): void
|
||||
{
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener($domainManager);
|
||||
|
||||
// request to auth subdomain with a stale auth-domain cookie
|
||||
$request = Request::create('https://auth.example.com/', 'GET');
|
||||
$request->cookies->set(self::AUTH_COOKIE_NAME, 'stale-ulid');
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$response = $event->getResponse();
|
||||
$cleared = false;
|
||||
foreach ($response->headers->getCookies() as $cookie) {
|
||||
if ($cookie->getName() === self::AUTH_COOKIE_NAME && $cookie->isCleared()) {
|
||||
$cleared = true;
|
||||
}
|
||||
}
|
||||
self::assertTrue($cleared, 'Expected the auth cookie to be cleared');
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,310 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Listener;
|
||||
|
||||
use App\Data\Payload;
|
||||
use App\Enum\Scope;
|
||||
use App\Listener\LoginListener;
|
||||
use App\Service\DomainManager;
|
||||
use App\Service\LoginInterface;
|
||||
use App\Tests\Support\ListenerTestHelper;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Symfony\Component\HttpKernel\HttpKernelInterface;
|
||||
|
||||
final class LoginListenerTest extends TestCase
|
||||
{
|
||||
use ListenerTestHelper;
|
||||
|
||||
private const string HEADER_NAME = 'X-Preauth';
|
||||
|
||||
private function makeListener(
|
||||
?LoginInterface $loginManager = null,
|
||||
?DomainManager $domainManager = null,
|
||||
?int $rateLimitRemaining = 5,
|
||||
): LoginListener {
|
||||
$listener = new LoginListener(
|
||||
$this->makeTwig(),
|
||||
$this->makeRateLimiterFactory($rateLimitRemaining ?? 5),
|
||||
$domainManager ?? new DomainManager(false, ''),
|
||||
$loginManager ?? $this->createStub(LoginInterface::class),
|
||||
$this->makeConfig(),
|
||||
);
|
||||
$listener->setLogger(new NullLogger());
|
||||
$listener->setNonceCache(new ArrayAdapter());
|
||||
return $listener;
|
||||
}
|
||||
|
||||
private function makeEvent(Request $request): RequestEvent
|
||||
{
|
||||
return new RequestEvent(
|
||||
$this->createStub(HttpKernelInterface::class),
|
||||
$request,
|
||||
HttpKernelInterface::MAIN_REQUEST,
|
||||
);
|
||||
}
|
||||
|
||||
/** Build a base64url-encoded X-Preauth header value for a payload. */
|
||||
private function encodePayload(array $data): string
|
||||
{
|
||||
$json = json_encode($data, JSON_THROW_ON_ERROR);
|
||||
return rtrim(strtr(base64_encode($json), '+/', '-_'), '=');
|
||||
}
|
||||
|
||||
/* ── no login attempt ─────────────────────────────────────────────── */
|
||||
|
||||
public function testNoHeaderAndNoPostReturnsEarlyWithoutResponse(): void
|
||||
{
|
||||
$listener = $this->makeListener();
|
||||
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
|
||||
public function testPostToNonAuthSubdomainReturnsEarlyWithoutResponse(): void
|
||||
{
|
||||
// POST only counts as a login attempt when on the auth subdomain
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener(domainManager: $domainManager);
|
||||
|
||||
$request = Request::create('https://app.example.com/', 'POST');
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
|
||||
/* ── successful login via header ──────────────────────────────────── */
|
||||
|
||||
public function testSuccessfulLoginViaHeaderSetsResponseFromManager(): void
|
||||
{
|
||||
$expected = new Response('hi alice', 200, ['Remote-User' => 'alice']);
|
||||
$loginManager = $this->createStub(LoginInterface::class);
|
||||
$loginManager->method('checkToken')->willReturn($expected);
|
||||
|
||||
$listener = $this->makeListener(loginManager: $loginManager);
|
||||
|
||||
$payload = $this->encodePayload([
|
||||
'id' => 'alice', 'token' => '123456', 'nonce' => 'nonce-1', 'json' => true,
|
||||
]);
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$request->headers->set(self::HEADER_NAME, $payload);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
self::assertSame($expected, $event->getResponse());
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginViaPostToAuthSubdomain(): void
|
||||
{
|
||||
$expected = new Response('hi bob', 303, ['Location' => '/']);
|
||||
$loginManager = $this->createStub(LoginInterface::class);
|
||||
$loginManager->method('checkToken')->willReturn($expected);
|
||||
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener(loginManager: $loginManager, domainManager: $domainManager);
|
||||
|
||||
$request = Request::create('https://auth.example.com/', 'POST', [
|
||||
'username' => 'bob', 'totp' => '654321', 'nonce' => 'nonce-2',
|
||||
]);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
self::assertSame($expected, $event->getResponse());
|
||||
}
|
||||
|
||||
/* ── failed login ─────────────────────────────────────────────────── */
|
||||
|
||||
public function testFailedLoginReturnsJsonErrorWithNewNonce(): void
|
||||
{
|
||||
$loginManager = $this->createStub(LoginInterface::class);
|
||||
$loginManager->method('checkToken')->willReturn(null);
|
||||
|
||||
$listener = $this->makeListener(loginManager: $loginManager);
|
||||
|
||||
$payload = $this->encodePayload([
|
||||
'id' => 'alice', 'token' => 'wrong', 'nonce' => 'nonce-1', 'json' => true,
|
||||
]);
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$request->headers->set(self::HEADER_NAME, $payload);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_UNAUTHORIZED, $response->getStatusCode());
|
||||
self::assertSame('application/json', $response->headers->get('Content-Type'));
|
||||
$body = json_decode($response->getContent(), true);
|
||||
// the TotpTestHelper::makeConfig default errorMessage is 'Error'
|
||||
self::assertSame('Error', $body['message']);
|
||||
self::assertNotEmpty($body['nonce']);
|
||||
self::assertFalse($body['post']);
|
||||
// username is echoed back (sanitized via makeCacheKey)
|
||||
self::assertSame('alice', $body['username']);
|
||||
}
|
||||
|
||||
public function testFailedLoginHtmlResponseWhenJsonFalse(): void
|
||||
{
|
||||
$loginManager = $this->createStub(LoginInterface::class);
|
||||
$loginManager->method('checkToken')->willReturn(null);
|
||||
|
||||
$listener = $this->makeListener(loginManager: $loginManager);
|
||||
|
||||
$payload = $this->encodePayload([
|
||||
'id' => 'alice', 'token' => 'wrong', 'nonce' => 'nonce-1', 'json' => false,
|
||||
]);
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$request->headers->set(self::HEADER_NAME, $payload);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_UNAUTHORIZED, $response->getStatusCode());
|
||||
self::assertSame('text/html', $response->headers->get('Content-Type'));
|
||||
self::assertStringContainsString('<form', $response->getContent());
|
||||
}
|
||||
|
||||
public function testFailedLoginOnAuthSubdomainUsesPostForm(): void
|
||||
{
|
||||
$loginManager = $this->createStub(LoginInterface::class);
|
||||
$loginManager->method('checkToken')->willReturn(null);
|
||||
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener(
|
||||
loginManager: $loginManager,
|
||||
domainManager: $domainManager,
|
||||
);
|
||||
|
||||
$payload = $this->encodePayload([
|
||||
'id' => 'alice', 'token' => 'wrong', 'nonce' => 'nonce-1', 'json' => false,
|
||||
]);
|
||||
$request = Request::create('https://auth.example.com/', 'GET');
|
||||
$request->headers->set(self::HEADER_NAME, $payload);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$content = $event->getResponse()->getContent();
|
||||
self::assertStringContainsString('method="post"', $content);
|
||||
}
|
||||
|
||||
/* ── rate-limited (blocked) login ─────────────────────────────────── */
|
||||
|
||||
public function testRateLimitedLoginReturnsTeapotWhenTeapotEnabled(): void
|
||||
{
|
||||
$loginManager = $this->createStub(LoginInterface::class);
|
||||
$loginManager->method('checkToken')->willReturn(null);
|
||||
|
||||
// limiter with 0 remaining tokens -> blocked
|
||||
$listener = $this->makeListener(
|
||||
loginManager: $loginManager,
|
||||
rateLimitRemaining: 0,
|
||||
);
|
||||
|
||||
$payload = $this->encodePayload([
|
||||
'id' => 'alice', 'token' => 'wrong', 'nonce' => 'nonce-1', 'json' => true,
|
||||
]);
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$request->headers->set(self::HEADER_NAME, $payload);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_I_AM_A_TEAPOT, $response->getStatusCode());
|
||||
$body = json_decode($response->getContent(), true);
|
||||
// the TotpTestHelper::makeConfig default teapotTitle is 'Teapot'
|
||||
self::assertSame('Teapot', $body['message']);
|
||||
}
|
||||
|
||||
public function testRateLimitedLoginReturnsTooManyRequestsWhenTeapotDisabled(): void
|
||||
{
|
||||
$loginManager = $this->createStub(LoginInterface::class);
|
||||
$loginManager->method('checkToken')->willReturn(null);
|
||||
|
||||
$listener = new LoginListener(
|
||||
$this->makeTwig(),
|
||||
$this->makeRateLimiterFactory(0),
|
||||
new DomainManager(false, ''),
|
||||
$loginManager,
|
||||
$this->makeConfig(teapot: false),
|
||||
);
|
||||
$listener->setLogger(new NullLogger());
|
||||
$listener->setNonceCache(new ArrayAdapter());
|
||||
|
||||
$payload = $this->encodePayload([
|
||||
'id' => 'alice', 'token' => 'wrong', 'nonce' => 'nonce-1', 'json' => true,
|
||||
]);
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$request->headers->set(self::HEADER_NAME, $payload);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_TOO_MANY_REQUESTS, $response->getStatusCode());
|
||||
$body = json_decode($response->getContent(), true);
|
||||
// teapot disabled, so tooManyTitle is used; helper default is 'Too Many'
|
||||
self::assertSame('Too Many', $body['message']);
|
||||
}
|
||||
|
||||
/* ── invalid payload handling ─────────────────────────────────────── */
|
||||
|
||||
public function testInvalidHeaderPayloadStillRecordsFailureAndResponds(): void
|
||||
{
|
||||
$loginManager = $this->createMock(LoginInterface::class);
|
||||
// checkToken should not be called with a null payload
|
||||
$loginManager->expects(self::never())->method('checkToken');
|
||||
|
||||
$listener = $this->makeListener(loginManager: $loginManager);
|
||||
|
||||
// an un-decodable header value
|
||||
$request = Request::create('https://example.com/', 'GET');
|
||||
$request->headers->set(self::HEADER_NAME, '!!!not-valid-base64!!!');
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
// Payload::decode returns null, so checkToken is skipped, but a
|
||||
// failure response is still produced (the rate limiter is consulted)
|
||||
self::assertTrue($event->hasResponse());
|
||||
self::assertSame(Response::HTTP_UNAUTHORIZED, $event->getResponse()->getStatusCode());
|
||||
}
|
||||
|
||||
public function testPostWithoutRequiredFieldsDoesNotAttemptLogin(): void
|
||||
{
|
||||
$loginManager = $this->createMock(LoginInterface::class);
|
||||
$loginManager->expects(self::never())->method('checkToken');
|
||||
|
||||
$domainManager = new DomainManager(true, 'auth.example.com');
|
||||
$listener = $this->makeListener(
|
||||
loginManager: $loginManager,
|
||||
domainManager: $domainManager,
|
||||
);
|
||||
|
||||
// POST to auth subdomain but missing the required fields
|
||||
$request = Request::create('https://auth.example.com/', 'POST', ['username' => 'only-user']);
|
||||
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
// Payload::load returns null (missing totp & nonce), so it falls through
|
||||
// to the failure path and produces a response
|
||||
self::assertTrue($event->hasResponse());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,96 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Listener;
|
||||
|
||||
use App\Listener\RejectListener;
|
||||
use App\Service\DomainManager;
|
||||
use App\Tests\Support\ListenerTestHelper;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Event\RequestEvent;
|
||||
use Symfony\Component\HttpKernel\HttpKernelInterface;
|
||||
|
||||
final class RejectListenerTest extends TestCase
|
||||
{
|
||||
use ListenerTestHelper;
|
||||
|
||||
private function makeListener(
|
||||
bool $teapot = true,
|
||||
int $remainingTokens = 5,
|
||||
): RejectListener {
|
||||
$listener = new RejectListener(
|
||||
$this->makeConfig(teapot: $teapot),
|
||||
$this->makeTwig(),
|
||||
$this->makeRateLimiterFactory($remainingTokens),
|
||||
);
|
||||
$listener->setLogger(new NullLogger());
|
||||
return $listener;
|
||||
}
|
||||
|
||||
private function makeEvent(Request $request): RequestEvent
|
||||
{
|
||||
return new RequestEvent(
|
||||
$this->createStub(HttpKernelInterface::class),
|
||||
$request,
|
||||
HttpKernelInterface::MAIN_REQUEST,
|
||||
);
|
||||
}
|
||||
|
||||
public function testBlockedRequestReturnsTeapotWhenTeapotEnabled(): void
|
||||
{
|
||||
$listener = $this->makeListener(teapot: true, remainingTokens: 0);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_I_AM_A_TEAPOT, $response->getStatusCode());
|
||||
self::assertSame('text/html', $response->headers->get('Content-Type'));
|
||||
}
|
||||
|
||||
public function testBlockedRequestReturnsTooManyRequestsWhenTeapotDisabled(): void
|
||||
{
|
||||
$listener = $this->makeListener(teapot: false, remainingTokens: 0);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
self::assertTrue($event->hasResponse());
|
||||
$response = $event->getResponse();
|
||||
self::assertSame(Response::HTTP_TOO_MANY_REQUESTS, $response->getStatusCode());
|
||||
self::assertSame('text/html', $response->headers->get('Content-Type'));
|
||||
}
|
||||
|
||||
public function testUnblockedRequestSetsNoResponse(): void
|
||||
{
|
||||
$listener = $this->makeListener(remainingTokens: 5);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
// consume(0) with remaining tokens > 0 should not block
|
||||
self::assertFalse($event->hasResponse());
|
||||
}
|
||||
|
||||
public function testBlockedResponseContainsErrorTemplateContent(): void
|
||||
{
|
||||
$listener = $this->makeListener(teapot: true, remainingTokens: 0);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
$event = $this->makeEvent($request);
|
||||
$listener->onKernelRequest($event);
|
||||
|
||||
$content = $event->getResponse()->getContent();
|
||||
// Twig escapes the apostrophe in "I'm a teapot" to '
|
||||
self::assertStringContainsString('a teapot', $content);
|
||||
self::assertStringContainsString('I refuse to brew coffee', $content);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,301 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit;
|
||||
|
||||
use App\MonitorCacheKeys;
|
||||
use OutOfBoundsException;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
|
||||
final class MonitorCacheKeysTest extends TestCase
|
||||
{
|
||||
private function wrap(?ArrayAdapter $pool = null): MonitorCacheKeys
|
||||
{
|
||||
$pool ??= new ArrayAdapter();
|
||||
return new MonitorCacheKeys($pool);
|
||||
}
|
||||
|
||||
public function testConstructorInitializesEmptyPool(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
self::assertSame([], $monitor->getKeys());
|
||||
self::assertSame([], $monitor->getChanges());
|
||||
}
|
||||
|
||||
public function testSaveAddsKeyAndTracksChange(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('alpha');
|
||||
$item->set('value');
|
||||
$monitor->save($item);
|
||||
|
||||
self::assertSame(['alpha'], $monitor->getKeys());
|
||||
self::assertSame(['alpha' => MonitorCacheKeys::UPDATED], $monitor->getChanges());
|
||||
}
|
||||
|
||||
public function testSaveDeferredThenCommitAddsKey(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('beta');
|
||||
$item->set('value');
|
||||
$monitor->saveDeferred($item);
|
||||
|
||||
// saveDeferred calls update() which commits immediately
|
||||
self::assertSame(['beta'], $monitor->getKeys());
|
||||
self::assertSame(['beta' => MonitorCacheKeys::UPDATED], $monitor->getChanges());
|
||||
}
|
||||
|
||||
public function testGetItemReturnsUnderlyingItem(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('mykey');
|
||||
$item->set('data');
|
||||
$monitor->save($item);
|
||||
|
||||
$fetched = $monitor->getItem('mykey');
|
||||
self::assertTrue($fetched->isHit());
|
||||
self::assertSame('data', $fetched->get());
|
||||
}
|
||||
|
||||
public function testGetItemsReturnsMultipleItems(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$a = $monitor->getItem('a');
|
||||
$a->set(1);
|
||||
$monitor->save($a);
|
||||
$b = $monitor->getItem('b');
|
||||
$b->set(2);
|
||||
$monitor->save($b);
|
||||
|
||||
$items = $monitor->getItems(['a', 'b']);
|
||||
$keys = [];
|
||||
foreach ($items as $key => $item) {
|
||||
$keys[$key] = $item->get();
|
||||
}
|
||||
self::assertSame(['a' => 1, 'b' => 2], $keys);
|
||||
}
|
||||
|
||||
public function testHasItemReturnsTrueForExistingKey(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('exists');
|
||||
$item->set('v');
|
||||
$monitor->save($item);
|
||||
|
||||
self::assertTrue($monitor->hasItem('exists'));
|
||||
self::assertFalse($monitor->hasItem('missing'));
|
||||
}
|
||||
|
||||
public function testDeleteItemRemovesKeyAndTracksRemoval(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('doomed');
|
||||
$item->set('v');
|
||||
$monitor->save($item);
|
||||
|
||||
$monitor->deleteItem('doomed');
|
||||
|
||||
self::assertSame([], $monitor->getKeys());
|
||||
self::assertSame(['doomed' => MonitorCacheKeys::REMOVED], $monitor->getChanges());
|
||||
self::assertFalse($monitor->hasItem('doomed'));
|
||||
}
|
||||
|
||||
public function testDeleteItemOnMissingKeyIsNoop(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
$result = $monitor->deleteItem('nonexistent');
|
||||
|
||||
self::assertTrue($result);
|
||||
self::assertSame([], $monitor->getKeys());
|
||||
}
|
||||
|
||||
public function testDeleteItemsRemovesMultipleKeys(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
foreach (['x', 'y', 'z'] as $key) {
|
||||
$item = $monitor->getItem($key);
|
||||
$item->set($key);
|
||||
$monitor->save($item);
|
||||
}
|
||||
|
||||
$monitor->deleteItems(['x', 'y']);
|
||||
|
||||
self::assertSame(['z'], $monitor->getKeys());
|
||||
$changes = $monitor->getChanges();
|
||||
self::assertSame(MonitorCacheKeys::REMOVED, $changes['x']);
|
||||
self::assertSame(MonitorCacheKeys::REMOVED, $changes['y']);
|
||||
}
|
||||
|
||||
public function testDeleteItemsWithMissingKeysStillReturnsTrue(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
$result = $monitor->deleteItems(['ghost1', 'ghost2']);
|
||||
|
||||
self::assertTrue($result);
|
||||
}
|
||||
|
||||
public function testClearWipesPoolWhenNotEmpty(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('keep');
|
||||
$item->set('v');
|
||||
$monitor->save($item);
|
||||
|
||||
$result = $monitor->clear();
|
||||
|
||||
self::assertTrue($result);
|
||||
self::assertSame([], $monitor->getKeys());
|
||||
}
|
||||
|
||||
public function testClearIsNoopWhenEmpty(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
$result = $monitor->clear();
|
||||
|
||||
self::assertTrue($result);
|
||||
}
|
||||
|
||||
public function testMarkCleanResetsChangeList(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('temp');
|
||||
$item->set('v');
|
||||
$monitor->save($item);
|
||||
|
||||
self::assertNotEmpty($monitor->getChanges());
|
||||
|
||||
$monitor->markClean();
|
||||
|
||||
self::assertSame([], $monitor->getChanges());
|
||||
self::assertSame(['temp'], $monitor->getKeys());
|
||||
}
|
||||
|
||||
public function testCommitPassesThrough(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
self::assertTrue($monitor->commit());
|
||||
}
|
||||
|
||||
public function testSaveKeyListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('__key_list');
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->save($item);
|
||||
}
|
||||
|
||||
public function testSaveChangeListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('__chg_list');
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->save($item);
|
||||
}
|
||||
|
||||
public function testDeleteKeyListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->deleteItem('__key_list');
|
||||
}
|
||||
|
||||
public function testDeleteChangeListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->deleteItem('__chg_list');
|
||||
}
|
||||
|
||||
public function testDeleteItemsWithKeyListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->deleteItems(['safe', '__key_list']);
|
||||
}
|
||||
|
||||
public function testDeleteItemsWithChangeListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->deleteItems(['__chg_list']);
|
||||
}
|
||||
|
||||
public function testSaveDeferredOnKeyListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('safe');
|
||||
$item->set('value');
|
||||
|
||||
// getItem returns the real item, but saveDeferred calls update() which
|
||||
// validates the key — so we need to get the __key_list item and try to save it
|
||||
$keyListItem = $monitor->getItem('__key_list');
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->saveDeferred($keyListItem);
|
||||
}
|
||||
|
||||
public function testSaveDeferredOnChangeListThrowsOutOfBoundsException(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$changeListItem = $monitor->getItem('__chg_list');
|
||||
|
||||
$this->expectException(OutOfBoundsException::class);
|
||||
$monitor->saveDeferred($changeListItem);
|
||||
}
|
||||
|
||||
public function testGetKeysReturnsEmptyArrayWhenKeyListMissing(): void
|
||||
{
|
||||
// If the underlying pool loses its key list, getKeys should return []
|
||||
$pool = new ArrayAdapter();
|
||||
$monitor = new MonitorCacheKeys($pool);
|
||||
|
||||
$item = $monitor->getItem('alpha');
|
||||
$item->set('value');
|
||||
$monitor->save($item);
|
||||
|
||||
// delete the key list directly from the underlying pool
|
||||
$pool->deleteItem('__key_list');
|
||||
|
||||
$monitor2 = new MonitorCacheKeys($pool);
|
||||
// the constructor will re-initialize since __key_list is missing
|
||||
// but getKeys on the new monitor should be empty
|
||||
self::assertSame([], $monitor2->getKeys());
|
||||
}
|
||||
|
||||
public function testDeleteItemReturnsTrueForExistingKey(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
$item = $monitor->getItem('to-delete');
|
||||
$item->set('value');
|
||||
$monitor->save($item);
|
||||
|
||||
self::assertTrue($monitor->deleteItem('to-delete'));
|
||||
self::assertNotContains('to-delete', $monitor->getKeys());
|
||||
}
|
||||
|
||||
public function testDeleteItemsReturnsTrue(): void
|
||||
{
|
||||
$monitor = $this->wrap();
|
||||
foreach (['a', 'b', 'c'] as $key) {
|
||||
$item = $monitor->getItem($key);
|
||||
$item->set('value');
|
||||
$monitor->save($item);
|
||||
}
|
||||
|
||||
self::assertTrue($monitor->deleteItems(['a', 'b', 'c']));
|
||||
self::assertSame([], $monitor->getKeys());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,231 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit;
|
||||
|
||||
use App\MonitorCacheKeys;
|
||||
use App\PersistCache;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
|
||||
final class PersistCacheTest extends TestCase
|
||||
{
|
||||
public function testBootWithEmptyStorageIsNoop(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
|
||||
// nothing was loaded since storage is empty
|
||||
$monitor = new MonitorCacheKeys($sessionCache);
|
||||
self::assertSame([], $monitor->getKeys());
|
||||
}
|
||||
|
||||
public function testBootLoadsFromStorageIntoCache(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
// populate storage with some session data
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
$item = $storageMonitor->getItem('cookie_abc');
|
||||
$item->set('user1');
|
||||
$storageMonitor->save($item);
|
||||
$storageMonitor->markClean();
|
||||
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
|
||||
// session cache should now contain the loaded data
|
||||
$cacheMonitor = new MonitorCacheKeys($sessionCache);
|
||||
self::assertContains('cookie_abc', $cacheMonitor->getKeys());
|
||||
self::assertSame('user1', $cacheMonitor->getItem('cookie_abc')->get());
|
||||
// boot should mark clean so no changes are pending
|
||||
self::assertSame([], $cacheMonitor->getChanges());
|
||||
}
|
||||
|
||||
public function testBootDoesNotReloadWhenCacheAlreadyWarm(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
// warm up the cache with existing data
|
||||
$cacheMonitor = new MonitorCacheKeys($sessionCache);
|
||||
$item = $cacheMonitor->getItem('cookie_existing');
|
||||
$item->set('old-user');
|
||||
$cacheMonitor->save($item);
|
||||
|
||||
// put different data in storage
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
$item = $storageMonitor->getItem('cookie_new');
|
||||
$item->set('new-user');
|
||||
$storageMonitor->save($item);
|
||||
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
|
||||
// existing data should be preserved, storage data NOT loaded
|
||||
$monitor = new MonitorCacheKeys($sessionCache);
|
||||
self::assertContains('cookie_existing', $monitor->getKeys());
|
||||
self::assertNotContains('cookie_new', $monitor->getKeys());
|
||||
}
|
||||
|
||||
public function testPersistWritesChangesToStorage(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
|
||||
// write something to the session cache
|
||||
$cacheMonitor = new MonitorCacheKeys($sessionCache);
|
||||
$item = $cacheMonitor->getItem('cookie_xyz');
|
||||
$item->set('user2');
|
||||
$cacheMonitor->save($item);
|
||||
|
||||
$persist->persist();
|
||||
|
||||
// storage should now contain the change
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
self::assertContains('cookie_xyz', $storageMonitor->getKeys());
|
||||
self::assertSame('user2', $storageMonitor->getItem('cookie_xyz')->get());
|
||||
}
|
||||
|
||||
public function testPersistHandlesRemovals(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
// seed storage with an item
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
$item = $storageMonitor->getItem('cookie_to_remove');
|
||||
$item->set('user3');
|
||||
$storageMonitor->save($item);
|
||||
$storageMonitor->markClean();
|
||||
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
|
||||
// now delete it from session cache
|
||||
$cacheMonitor = new MonitorCacheKeys($sessionCache);
|
||||
$cacheMonitor->deleteItem('cookie_to_remove');
|
||||
|
||||
$persist->persist();
|
||||
|
||||
// storage should no longer have it
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
self::assertNotContains('cookie_to_remove', $storageMonitor->getKeys());
|
||||
}
|
||||
|
||||
public function testPersistIsNoopWhenNoChanges(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
$persist->persist();
|
||||
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
self::assertSame([], $storageMonitor->getKeys());
|
||||
}
|
||||
|
||||
public function testFullBootModifyPersistCycle(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
// boot (empty), add data, persist
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
|
||||
$cacheMonitor = new MonitorCacheKeys($sessionCache);
|
||||
$item = $cacheMonitor->getItem('cookie_cycle');
|
||||
$item->set('cycled-user');
|
||||
$cacheMonitor->save($item);
|
||||
|
||||
$persist->persist();
|
||||
|
||||
// simulate a new request: fresh cache, same storage
|
||||
$newCache = new ArrayAdapter();
|
||||
$persist2 = new PersistCache($newCache, $sessionStorage);
|
||||
$persist2->boot();
|
||||
|
||||
$monitor = new MonitorCacheKeys($newCache);
|
||||
self::assertContains('cookie_cycle', $monitor->getKeys());
|
||||
self::assertSame('cycled-user', $monitor->getItem('cookie_cycle')->get());
|
||||
}
|
||||
|
||||
public function testPersistHandlesMixedUpdatesAndRemovals(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
// seed storage with two items
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
$item1 = $storageMonitor->getItem('cookie_keep');
|
||||
$item1->set('user-keep');
|
||||
$storageMonitor->save($item1);
|
||||
$item2 = $storageMonitor->getItem('cookie_remove');
|
||||
$item2->set('user-remove');
|
||||
$storageMonitor->save($item2);
|
||||
$storageMonitor->markClean();
|
||||
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
|
||||
// update one item and delete the other in the same cycle
|
||||
$cacheMonitor = new MonitorCacheKeys($sessionCache);
|
||||
$item1 = $cacheMonitor->getItem('cookie_keep');
|
||||
$item1->set('user-updated');
|
||||
$cacheMonitor->save($item1);
|
||||
$cacheMonitor->deleteItem('cookie_remove');
|
||||
|
||||
$persist->persist();
|
||||
|
||||
// storage should reflect both changes
|
||||
$storageMonitor = new MonitorCacheKeys($sessionStorage);
|
||||
self::assertContains('cookie_keep', $storageMonitor->getKeys());
|
||||
self::assertSame('user-updated', $storageMonitor->getItem('cookie_keep')->get());
|
||||
self::assertNotContains('cookie_remove', $storageMonitor->getKeys());
|
||||
}
|
||||
|
||||
public function testMultipleBootModifyPersistCycles(): void
|
||||
{
|
||||
$sessionCache = new ArrayAdapter();
|
||||
$sessionStorage = new ArrayAdapter();
|
||||
|
||||
// cycle 1: add item A
|
||||
$persist = new PersistCache($sessionCache, $sessionStorage);
|
||||
$persist->boot();
|
||||
$cacheMonitor = new MonitorCacheKeys($sessionCache);
|
||||
$item = $cacheMonitor->getItem('cookie_a');
|
||||
$item->set('user-a');
|
||||
$cacheMonitor->save($item);
|
||||
$persist->persist();
|
||||
|
||||
// cycle 2: fresh cache, add item B, keep A from storage
|
||||
$newCache = new ArrayAdapter();
|
||||
$persist2 = new PersistCache($newCache, $sessionStorage);
|
||||
$persist2->boot();
|
||||
$cacheMonitor2 = new MonitorCacheKeys($newCache);
|
||||
$item = $cacheMonitor2->getItem('cookie_b');
|
||||
$item->set('user-b');
|
||||
$cacheMonitor2->save($item);
|
||||
$persist2->persist();
|
||||
|
||||
// cycle 3: fresh cache, both A and B should be loaded from storage
|
||||
$newCache2 = new ArrayAdapter();
|
||||
$persist3 = new PersistCache($newCache2, $sessionStorage);
|
||||
$persist3->boot();
|
||||
$monitor = new MonitorCacheKeys($newCache2);
|
||||
self::assertContains('cookie_a', $monitor->getKeys());
|
||||
self::assertSame('user-a', $monitor->getItem('cookie_a')->get());
|
||||
self::assertContains('cookie_b', $monitor->getKeys());
|
||||
self::assertSame('user-b', $monitor->getItem('cookie_b')->get());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,235 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Service;
|
||||
|
||||
use App\Service\BackupCodeManager;
|
||||
use App\Tests\Support\TotpTestHelper;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
|
||||
final class BackupCodeManagerTest extends TestCase
|
||||
{
|
||||
use TotpTestHelper;
|
||||
|
||||
private function makeManager(?ArrayAdapter $pool = null): BackupCodeManager
|
||||
{
|
||||
$pool ??= new ArrayAdapter();
|
||||
$manager = new BackupCodeManager($pool);
|
||||
$manager->setConfig($this->makeConfig());
|
||||
$manager->setLogger(new NullLogger());
|
||||
return $manager;
|
||||
}
|
||||
|
||||
public function testGenerateReturnsRequestedCount(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
|
||||
$codes = $manager->generate(5);
|
||||
|
||||
self::assertCount(5, $codes);
|
||||
foreach ($codes as $code) {
|
||||
self::assertIsString($code);
|
||||
// codes are lowercase alphanumeric
|
||||
self::assertMatchesRegularExpression('/^[a-z0-9]+$/', $code);
|
||||
}
|
||||
}
|
||||
|
||||
public function testGenerateDefaultCount(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
|
||||
$codes = $manager->generate();
|
||||
|
||||
self::assertCount(10, $codes);
|
||||
}
|
||||
|
||||
public function testGenerateZeroReturnsEmptyArray(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
|
||||
$codes = $manager->generate(0);
|
||||
|
||||
self::assertSame([], $codes);
|
||||
}
|
||||
|
||||
public function testGeneratedCodesAreStoredInCache(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$manager = $this->makeManager($pool);
|
||||
|
||||
$codes = $manager->generate(3);
|
||||
|
||||
// each code should be stored as a backup_ key
|
||||
foreach ($codes as $code) {
|
||||
$key = 'backup_' . strtolower($code);
|
||||
// the manager uses makeCacheKey which sanitizes, but for alphanumeric it's identity
|
||||
$item = $pool->getItem($key);
|
||||
self::assertTrue($item->isHit(), "Expected cache hit for key: $key");
|
||||
self::assertTrue($item->get(), "Expected code to be marked valid (true)");
|
||||
}
|
||||
}
|
||||
|
||||
public function testGeneratedCodesHaveFarFutureExpiry(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$manager = $this->makeManager($pool);
|
||||
|
||||
$codes = $manager->generate(1);
|
||||
$code = $codes[0];
|
||||
|
||||
$item = $pool->getItem('backup_' . strtolower($code));
|
||||
$expiry = $item->getMetadata()['expiry'];
|
||||
self::assertGreaterThan((new \DateTimeImmutable('+10 years'))->getTimestamp(), (int) $expiry);
|
||||
}
|
||||
|
||||
public function testVerifyAndConsumeValidCode(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
$codes = $manager->generate(2);
|
||||
|
||||
$code = $codes[0];
|
||||
|
||||
self::assertTrue($manager->verifyAndConsume($code));
|
||||
}
|
||||
|
||||
public function testVerifyAndConsumeMarksCodeAsUsed(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$manager = $this->makeManager($pool);
|
||||
$codes = $manager->generate(1);
|
||||
$code = $codes[0];
|
||||
|
||||
// first use succeeds
|
||||
self::assertTrue($manager->verifyAndConsume($code));
|
||||
|
||||
// second use fails (already consumed)
|
||||
self::assertFalse($manager->verifyAndConsume($code));
|
||||
}
|
||||
|
||||
public function testVerifyAndConsumeInvalidCode(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
|
||||
self::assertFalse($manager->verifyAndConsume('nonexistent_code'));
|
||||
}
|
||||
|
||||
public function testVerifyAndConsumeIsCaseInsensitive(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
$codes = $manager->generate(1);
|
||||
$code = $codes[0];
|
||||
|
||||
// uppercase version should still work
|
||||
self::assertTrue($manager->verifyAndConsume(strtoupper($code)));
|
||||
}
|
||||
|
||||
public function testVerifyAndConsumeStripsInvalidCharacters(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
$codes = $manager->generate(1);
|
||||
$code = $codes[0];
|
||||
|
||||
// inject spaces and special chars — should be stripped
|
||||
self::assertTrue($manager->verifyAndConsume(' ' . $code . '!!'));
|
||||
}
|
||||
|
||||
public function testExpireRemovesAllBackupCodes(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$manager = $this->makeManager($pool);
|
||||
$codes = $manager->generate(5);
|
||||
|
||||
$manager->expire();
|
||||
|
||||
// all backup keys should be gone
|
||||
foreach ($codes as $code) {
|
||||
self::assertFalse($pool->hasItem('backup_' . strtolower($code)));
|
||||
}
|
||||
}
|
||||
|
||||
public function testExpireWhenNoBackupCodesIsNoop(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$manager = $this->makeManager($pool);
|
||||
|
||||
// should not throw
|
||||
$manager->expire();
|
||||
|
||||
// this passes if no exception was thrown
|
||||
self::assertTrue(true);
|
||||
}
|
||||
|
||||
public function testExpireRemovesOnlyBackupPrefixedKeys(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$manager = $this->makeManager($pool);
|
||||
|
||||
$codes = $manager->generate(3);
|
||||
|
||||
// add a non-backup key
|
||||
$item = $pool->getItem('cookie_session');
|
||||
$item->set('data');
|
||||
$pool->save($item);
|
||||
|
||||
$manager->expire();
|
||||
|
||||
// non-backup key survives
|
||||
self::assertTrue($pool->hasItem('cookie_session'));
|
||||
|
||||
// backup keys are gone
|
||||
foreach ($codes as $code) {
|
||||
self::assertFalse($pool->hasItem('backup_' . strtolower($code)));
|
||||
}
|
||||
}
|
||||
|
||||
public function testVerifyAndConsumeEmptyStringReturnsFalse(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
|
||||
// empty string after preg_replace becomes 'backup_' with nothing after it
|
||||
self::assertFalse($manager->verifyAndConsume(''));
|
||||
}
|
||||
|
||||
public function testVerifyAndConsumeCodeWithValueFalseReturnsFalse(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$manager = $this->makeManager($pool);
|
||||
$codes = $manager->generate(1);
|
||||
$code = $codes[0];
|
||||
|
||||
// first use succeeds
|
||||
self::assertTrue($manager->verifyAndConsume($code));
|
||||
|
||||
// the code is now marked as false (used); isHit is true but get() is false
|
||||
$key = 'backup_' . strtolower($code);
|
||||
$item = $pool->getItem($key);
|
||||
self::assertTrue($item->isHit());
|
||||
self::assertFalse($item->get());
|
||||
|
||||
// second use should fail because get() returns false
|
||||
self::assertFalse($manager->verifyAndConsume($code));
|
||||
}
|
||||
|
||||
public function testGenerateProducesUniqueCodes(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
|
||||
$codes = $manager->generate(50);
|
||||
|
||||
self::assertCount(50, $codes);
|
||||
self::assertCount(50, array_unique($codes), 'All generated codes should be unique');
|
||||
}
|
||||
|
||||
public function testGenerateCodeLengthIsDigitsPlusTwo(): void
|
||||
{
|
||||
$manager = $this->makeManager();
|
||||
|
||||
$codes = $manager->generate(1);
|
||||
|
||||
// default TOTP digits is 6, so code length should be 6 + 2 = 8
|
||||
self::assertSame(8, strlen($codes[0]));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,278 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Service;
|
||||
|
||||
use App\Service\DomainManager;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
|
||||
final class DomainManagerTest extends TestCase
|
||||
{
|
||||
private function createManager(bool $subdomainRedirect, string $authSubdomain): DomainManager
|
||||
{
|
||||
return new DomainManager($subdomainRedirect, $authSubdomain);
|
||||
}
|
||||
|
||||
/* ── authBase / getAuthSubdomain ─────────────────────────────────────── */
|
||||
|
||||
public function testAuthBaseIsNullWhenSubdomainRedirectIsDisabled(): void
|
||||
{
|
||||
$manager = $this->createManager(false, 'auth.example.com');
|
||||
self::assertNull($manager->authBase());
|
||||
self::assertNull($manager->getAuthSubdomain());
|
||||
}
|
||||
|
||||
public function testAuthBaseIsNullWhenAuthSubdomainIsEmpty(): void
|
||||
{
|
||||
$manager = $this->createManager(true, '');
|
||||
self::assertNull($manager->authBase());
|
||||
self::assertNull($manager->getAuthSubdomain());
|
||||
}
|
||||
|
||||
public function testAuthBaseExtractsSimpleDomain(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertSame('example.com', $manager->authBase());
|
||||
self::assertSame('auth.example.com', $manager->getAuthSubdomain());
|
||||
}
|
||||
|
||||
public function testAuthBaseExtractsMultiPartTld(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.co.uk');
|
||||
self::assertSame('example.co.uk', $manager->authBase());
|
||||
self::assertSame('auth.example.co.uk', $manager->getAuthSubdomain());
|
||||
}
|
||||
|
||||
public function testAuthBaseIsNullForLocalhostAuth(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'localhost');
|
||||
self::assertNull($manager->authBase());
|
||||
self::assertNull($manager->getAuthSubdomain());
|
||||
}
|
||||
|
||||
public function testAuthBaseIsNullForIpAuth(): void
|
||||
{
|
||||
$manager = $this->createManager(true, '192.168.1.1');
|
||||
self::assertNull($manager->authBase());
|
||||
self::assertNull($manager->getAuthSubdomain());
|
||||
}
|
||||
|
||||
/* ── validReturn ──────────────────────────────────────────────────────── */
|
||||
|
||||
public function testValidReturnAcceptsAnyUrlWhenNoSubdomain(): void
|
||||
{
|
||||
$manager = $this->createManager(false, '');
|
||||
self::assertTrue($manager->validReturn('https://evil.com/page'));
|
||||
self::assertTrue($manager->validReturn('https://example.com/ok'));
|
||||
}
|
||||
|
||||
public function testValidReturnRejectsInvalidUrl(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->validReturn('not-a-url'));
|
||||
self::assertFalse($manager->validReturn(''));
|
||||
}
|
||||
|
||||
public function testValidReturnAcceptsSameBaseDomain(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertTrue($manager->validReturn('https://app.example.com/dashboard'));
|
||||
self::assertTrue($manager->validReturn('https://example.com/'));
|
||||
}
|
||||
|
||||
public function testValidReturnRejectsDifferentBaseDomain(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->validReturn('https://evil.com/phish'));
|
||||
self::assertFalse($manager->validReturn('https://other-example.com/'));
|
||||
}
|
||||
|
||||
public function testValidReturnHandlesCoUkTld(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.co.uk');
|
||||
self::assertTrue($manager->validReturn('https://www.example.co.uk/'));
|
||||
self::assertFalse($manager->validReturn('https://example.com/'));
|
||||
}
|
||||
|
||||
public function testValidReturnRejectsUrlWithoutHost(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->validReturn('mailto:test@example.com'));
|
||||
}
|
||||
|
||||
/* ── matchesAuth ──────────────────────────────────────────────────────── */
|
||||
|
||||
public function testMatchesAuthIsFalseWhenSubdomainRedirectDisabled(): void
|
||||
{
|
||||
$manager = $this->createManager(false, 'auth.example.com');
|
||||
self::assertFalse($manager->matchesAuth('example.com'));
|
||||
self::assertFalse($manager->matchesAuth('app.example.com'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthIsFalseWhenAuthSubdomainIsEmpty(): void
|
||||
{
|
||||
$manager = $this->createManager(true, '');
|
||||
self::assertFalse($manager->matchesAuth('example.com'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthMatchesSameBaseDomain(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertTrue($manager->matchesAuth('example.com'));
|
||||
self::assertTrue($manager->matchesAuth('app.example.com'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthRejectsDifferentBaseDomain(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->matchesAuth('evil.com'));
|
||||
self::assertFalse($manager->matchesAuth('example.org'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthHandlesMultiPartTld(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.co.uk');
|
||||
self::assertTrue($manager->matchesAuth('www.example.co.uk'));
|
||||
self::assertFalse($manager->matchesAuth('example.com'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthRejectsIpHost(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->matchesAuth('192.168.1.1'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthRejectsLocalhost(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->matchesAuth('localhost'));
|
||||
}
|
||||
|
||||
/* ── baseDomain edge cases via matchesAuth ────────────────────────────── */
|
||||
|
||||
public function testMatchesAuthWithDeepSubdomain(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertTrue($manager->matchesAuth('a.b.c.example.com'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithTwoPartDomain(): void
|
||||
{
|
||||
/* for a 2-part auth subdomain, the baseDomain retains both parts */
|
||||
$manager = $this->createManager(true, 'auth.local');
|
||||
self::assertSame('auth.local', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('auth.local'));
|
||||
self::assertFalse($manager->matchesAuth('local'));
|
||||
self::assertFalse($manager->matchesAuth('app.local'));
|
||||
}
|
||||
|
||||
/* ── TLD table coverage ──────────────────────────────────────────────── */
|
||||
|
||||
public function testMatchesAuthWithComAuTld(): void
|
||||
{
|
||||
// com.au is NOT in the TLD table (table has au? no, it doesn't),
|
||||
// so it's treated as a standard 2-part TLD: base = com.au
|
||||
$manager = $this->createManager(true, 'auth.example.com.au');
|
||||
self::assertSame('com.au', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('app.example.com.au'));
|
||||
self::assertFalse($manager->matchesAuth('example.com'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithCoJpTld(): void
|
||||
{
|
||||
// co.jp is NOT in the TLD table (table has jpn under com, not jp under co)
|
||||
// so base = co.jp
|
||||
$manager = $this->createManager(true, 'auth.example.co.jp');
|
||||
self::assertSame('co.jp', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('www.example.co.jp'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithComBrTld(): void
|
||||
{
|
||||
// com.br: TLD table has com => [br], meaning *.br.com is multi-part
|
||||
// but com.br has last=br, TLD['br'] doesn't exist, so base = com.br
|
||||
$manager = $this->createManager(true, 'auth.example.com.br');
|
||||
self::assertSame('com.br', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('app.example.com.br'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithCoNzTld(): void
|
||||
{
|
||||
// co.nz is NOT in the TLD table (nz => [co,net,org], so *.co.nz IS multi-part)
|
||||
$manager = $this->createManager(true, 'auth.example.co.nz');
|
||||
self::assertSame('example.co.nz', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('sub.example.co.nz'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithComMxTld(): void
|
||||
{
|
||||
// com.mx is NOT in the TLD table (mx => [com,net,org], so *.com.mx IS multi-part)
|
||||
$manager = $this->createManager(true, 'auth.example.com.mx');
|
||||
self::assertSame('example.com.mx', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('app.example.com.mx'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithCoInTld(): void
|
||||
{
|
||||
// co.in: in => [co,...], so *.co.in IS multi-part
|
||||
$manager = $this->createManager(true, 'auth.example.co.in');
|
||||
self::assertSame('example.co.in', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('app.example.co.in'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithBrComTld(): void
|
||||
{
|
||||
// br.com: TLD table has com => [br], so *.br.com IS multi-part
|
||||
$manager = $this->createManager(true, 'auth.example.br.com');
|
||||
self::assertSame('example.br.com', $manager->authBase());
|
||||
self::assertTrue($manager->matchesAuth('app.example.br.com'));
|
||||
}
|
||||
|
||||
public function testSimpleTldNotTreatedAsMultiPart(): void
|
||||
{
|
||||
// example.com is a standard 2-part domain, not multi-part
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertSame('example.com', $manager->authBase());
|
||||
// auth.example.org should NOT match example.com
|
||||
self::assertFalse($manager->matchesAuth('app.example.org'));
|
||||
}
|
||||
|
||||
/* ── baseDomain edge cases ───────────────────────────────────────────── */
|
||||
|
||||
public function testMatchesAuthWithSingleLabelHost(): void
|
||||
{
|
||||
// a single-label domain (not localhost, not IP) has baseLength 1
|
||||
// so 'myhost' has baseDomain 'myhost', while 'auth.local' has base 'auth.local'
|
||||
// they won't match unless the auth subdomain itself is single-label
|
||||
$manager = $this->createManager(true, 'auth.local');
|
||||
// auth.local base is 'auth.local', 'local' base is 'local' -> no match
|
||||
self::assertFalse($manager->matchesAuth('local'));
|
||||
// but a subdomain of auth.local does match
|
||||
self::assertTrue($manager->matchesAuth('app.auth.local'));
|
||||
}
|
||||
|
||||
public function testMatchesAuthWithEmptyStringHost(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->matchesAuth(''));
|
||||
}
|
||||
|
||||
public function testValidReturnAcceptsUrlWithPort(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertTrue($manager->validReturn('https://example.com:8080/path'));
|
||||
}
|
||||
|
||||
public function testValidReturnAcceptsUrlWithoutPath(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertTrue($manager->validReturn('https://example.com'));
|
||||
}
|
||||
|
||||
public function testValidReturnRejectsDifferentDomainWithPort(): void
|
||||
{
|
||||
$manager = $this->createManager(true, 'auth.example.com');
|
||||
self::assertFalse($manager->validReturn('https://evil.com:8080/path'));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,445 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Service;
|
||||
|
||||
use App\Data\Payload;
|
||||
use App\Enum\Scope;
|
||||
use App\Service\BackupCodeInterface;
|
||||
use App\Service\DomainManager;
|
||||
use App\Trait\StringTrait;
|
||||
use App\Service\LoginManager;
|
||||
use App\Tests\Support\TotpTestHelper;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Cache\CacheItemInterface;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
|
||||
final class LoginManagerTest extends TestCase
|
||||
{
|
||||
use TotpTestHelper;
|
||||
use StringTrait;
|
||||
|
||||
private ArrayAdapter $pool;
|
||||
private BackupCodeInterface $backupCodeManager;
|
||||
private DomainManager $domainManager;
|
||||
|
||||
private function makeLoginManager(
|
||||
?int $ipTtl = 0,
|
||||
bool $subdomainRedirect = false,
|
||||
string $authSubdomain = '',
|
||||
): LoginManager {
|
||||
$this->pool = new ArrayAdapter();
|
||||
$this->backupCodeManager = $this->createStub(BackupCodeInterface::class);
|
||||
$this->domainManager = new DomainManager($subdomainRedirect, $authSubdomain);
|
||||
|
||||
$manager = new LoginManager($this->pool, $this->backupCodeManager, $this->domainManager);
|
||||
$manager->setConfig($this->makeConfig(ipTtl: $ipTtl));
|
||||
$manager->setLogger(new NullLogger());
|
||||
$manager->setNonceCache(new ArrayAdapter());
|
||||
return $manager;
|
||||
}
|
||||
|
||||
/** Build a Payload with a valid server-side nonce already stored. */
|
||||
private function makePayloadWithNonce(
|
||||
LoginManager $manager,
|
||||
string $id = 'testuser',
|
||||
Scope $scope = Scope::Cookie,
|
||||
?string $token = null,
|
||||
): Payload {
|
||||
$token ??= $this->validTotpCode();
|
||||
$nonce = $this->insertNonce($manager, 'test-nonce-123');
|
||||
|
||||
$payload = new Payload();
|
||||
$payload->id = $id;
|
||||
$payload->token = $token;
|
||||
$payload->nonce = $nonce;
|
||||
$payload->json = true;
|
||||
$payload->scope = $scope;
|
||||
return $payload;
|
||||
}
|
||||
|
||||
/** Inject a nonce directly into the manager's nonce cache. */
|
||||
private function insertNonce(LoginManager $manager, string $nonce): string
|
||||
{
|
||||
$reflection = new \ReflectionProperty(LoginManager::class, 'nonceCache');
|
||||
$nonceCache = $reflection->getValue($manager);
|
||||
|
||||
$key = $this->makeCacheKey($nonce);
|
||||
$item = $nonceCache->getItem($key);
|
||||
$item->set(true);
|
||||
$nonceCache->save($item);
|
||||
|
||||
return $nonce;
|
||||
}
|
||||
|
||||
public function testCheckTokenReturnsNullForInvalidTotp(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, token: 'wrong-code');
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
self::assertNull($manager->checkToken($payload, $request));
|
||||
}
|
||||
|
||||
public function testCheckTokenReturnsNullForSpentNonce(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
// spend the nonce first (use the same cache key the manager does)
|
||||
$reflection = new \ReflectionProperty(LoginManager::class, 'nonceCache');
|
||||
$nonceCache = $reflection->getValue($manager);
|
||||
$nonceItem = $nonceCache->getItem($this->makeCacheKey('test-nonce-123'));
|
||||
$nonceItem->set(false);
|
||||
$nonceCache->save($nonceItem);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
self::assertNull($manager->checkToken($payload, $request));
|
||||
}
|
||||
|
||||
public function testCheckTokenReturnsNullForMissingNonce(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$payload = new Payload();
|
||||
$payload->id = 'user1';
|
||||
$payload->token = $this->validTotpCode();
|
||||
$payload->nonce = 'never-stored';
|
||||
$payload->json = true;
|
||||
$payload->scope = Scope::Cookie;
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
self::assertNull($manager->checkToken($payload, $request));
|
||||
}
|
||||
|
||||
public function testSuccessfulTotpLoginWithCookieScopeReturnsRedirect(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Cookie);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/dashboard', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
self::assertSame(303, $response->getStatusCode()); // HTTP_SEE_OTHER
|
||||
self::assertTrue($response->headers->has('Location'));
|
||||
self::assertTrue($response->headers->has('Set-Cookie'));
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginWithNoneScopeReturnsPlainResponse(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::None);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
self::assertSame(200, $response->getStatusCode());
|
||||
self::assertSame('text/plain', $response->headers->get('Content-Type'));
|
||||
self::assertTrue($response->headers->has('Remote-User'));
|
||||
// no redirect for Scope::None
|
||||
self::assertFalse($response->headers->has('Location'));
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginSetsRemoteUserHeader(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, id: 'alice', scope: Scope::None);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
self::assertSame('alice', $response->headers->get('Remote-User'));
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginJsonResponse(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Cookie, token: null);
|
||||
$payload->json = true;
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/protected', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
self::assertSame('application/json', $response->headers->get('Content-Type'));
|
||||
$body = json_decode($response->getContent(), true);
|
||||
self::assertSame('Login successful', $body['message']);
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginHtmlResponse(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Cookie);
|
||||
$payload->json = false;
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/protected', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
self::assertSame('text/html', $response->headers->get('Content-Type'));
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginWithReturnUrl(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Cookie);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/login?return=https://example.com/app', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
self::assertSame('https://example.com/app', $response->headers->get('Location'));
|
||||
}
|
||||
|
||||
public function testSuccessfulLoginWithInvalidReturnFallsBackToPath(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Cookie);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/login?return=not-a-url', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
$location = $response->headers->get('Location');
|
||||
self::assertStringStartsWith('/login', $location);
|
||||
}
|
||||
|
||||
public function testIpScopeDowngradesToCookieWhenIpAccessDisabled(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager(ipTtl: 0);
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Ip);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
// Should have a Set-Cookie (downgraded to cookie scope)
|
||||
self::assertNotNull($response);
|
||||
self::assertTrue($response->headers->has('Set-Cookie'));
|
||||
}
|
||||
|
||||
public function testIpScopeWhenEnabledSetsIpSession(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager(ipTtl: 1800);
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Ip);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/', 'GET', [], [], [], ['REMOTE_ADDR' => '1.2.3.4']);
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
// IP session should be stored; no Set-Cookie for IP scope
|
||||
self::assertFalse($response->headers->has('Set-Cookie'));
|
||||
|
||||
// verify the IP session exists in the cache
|
||||
$reflection = new \ReflectionProperty(LoginManager::class, 'sessionCache');
|
||||
$sessionCache = $reflection->getValue($manager);
|
||||
self::assertTrue($sessionCache->hasItem('ip_1.2.3.4'));
|
||||
}
|
||||
|
||||
public function testBackupCodeAuthentication(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, token: 'backup-code-123');
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(true);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
self::assertSame(303, $response->getStatusCode());
|
||||
}
|
||||
|
||||
public function testNonceIsConsumedAfterSuccessfulLogin(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
$manager->checkToken($payload, $request);
|
||||
|
||||
// nonce should now be marked invalid (false); look it up via the same
|
||||
// cache key the manager uses (makeCacheKey rewrites '-' to '_')
|
||||
$reflection = new \ReflectionProperty(LoginManager::class, 'nonceCache');
|
||||
$nonceCache = $reflection->getValue($manager);
|
||||
$nonceItem = $nonceCache->getItem($this->makeCacheKey('test-nonce-123'));
|
||||
self::assertFalse($nonceItem->get());
|
||||
}
|
||||
|
||||
public function testUlidCollisionThrowsHttpException(): void
|
||||
{
|
||||
// Use a stub pool where every cookie_ key is already a hit (collision)
|
||||
$pool = $this->createStub(CacheItemPoolInterface::class);
|
||||
$item = $this->createStub(CacheItemInterface::class);
|
||||
$item->method('isHit')->willReturn(true);
|
||||
$item->method('get')->willReturn('existing');
|
||||
// The nonce cache needs to work, so we return the stub item for
|
||||
// cookie_ keys but a real working item for nonce keys.
|
||||
$pool->method('getItem')->willReturnCallback(function (string $key) use ($item) {
|
||||
if (str_starts_with($key, 'cookie_')) {
|
||||
return $item; // collision
|
||||
}
|
||||
// For nonce keys, return a real item from an ArrayAdapter
|
||||
static $realPool = null;
|
||||
$realPool ??= new \Symfony\Component\Cache\Adapter\ArrayAdapter();
|
||||
return $realPool->getItem($key);
|
||||
});
|
||||
$pool->method('hasItem')->willReturnCallback(function (string $key) use ($item) {
|
||||
if (str_starts_with($key, 'cookie_')) {
|
||||
return true;
|
||||
}
|
||||
static $realPool = null;
|
||||
$realPool ??= new \Symfony\Component\Cache\Adapter\ArrayAdapter();
|
||||
return $realPool->hasItem($key);
|
||||
});
|
||||
$pool->method('save')->willReturn(true);
|
||||
$pool->method('saveDeferred')->willReturn(true);
|
||||
$pool->method('commit')->willReturn(true);
|
||||
$pool->method('getItems')->willReturnCallback(function (array $keys) {
|
||||
static $realPool = null;
|
||||
$realPool ??= new \Symfony\Component\Cache\Adapter\ArrayAdapter();
|
||||
return $realPool->getItems($keys);
|
||||
});
|
||||
$pool->method('clear')->willReturn(true);
|
||||
$pool->method('deleteItem')->willReturn(true);
|
||||
$pool->method('deleteItems')->willReturn(true);
|
||||
|
||||
$this->domainManager = new DomainManager(false, '');
|
||||
$this->backupCodeManager = $this->createStub(BackupCodeInterface::class);
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
$manager = new LoginManager($pool, $this->backupCodeManager, $this->domainManager);
|
||||
$manager->setConfig($this->makeConfig());
|
||||
$manager->setLogger(new NullLogger());
|
||||
$manager->setNonceCache(new \Symfony\Component\Cache\Adapter\ArrayAdapter());
|
||||
|
||||
$payload = new Payload();
|
||||
$payload->id = 'collide-user';
|
||||
$payload->token = $this->validTotpCode();
|
||||
$payload->nonce = 'test-nonce-123';
|
||||
$payload->json = true;
|
||||
$payload->scope = Scope::Cookie;
|
||||
|
||||
// inject the nonce
|
||||
$this->insertNonce($manager, 'test-nonce-123');
|
||||
|
||||
$request = Request::create('/', 'GET');
|
||||
|
||||
$this->expectException(HttpException::class);
|
||||
$manager->checkToken($payload, $request);
|
||||
}
|
||||
|
||||
public function testCookieScopeWithCentralAuthSetsDomainOnMatchingHost(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager(
|
||||
subdomainRedirect: true,
|
||||
authSubdomain: 'auth.example.com',
|
||||
);
|
||||
$payload = $this->makePayloadWithNonce($manager, id: 'alice', scope: Scope::Cookie);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
// host matches the auth base domain
|
||||
$request = Request::create('https://auth.example.com/', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
$cookies = $response->headers->getCookies();
|
||||
self::assertCount(1, $cookies);
|
||||
// when using central auth and host matches, the cookie domain is set
|
||||
self::assertSame('example.com', $cookies[0]->getDomain());
|
||||
// the auth cookie name is used instead of the host-prefixed name
|
||||
self::assertSame('__Http-Domain-Preauth', $cookies[0]->getName());
|
||||
}
|
||||
|
||||
public function testCookieScopeWithCentralAuthOnNonMatchingHostUsesNullDomain(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager(
|
||||
subdomainRedirect: true,
|
||||
authSubdomain: 'auth.example.com',
|
||||
);
|
||||
$payload = $this->makePayloadWithNonce($manager, id: 'bob', scope: Scope::Cookie);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
// host does NOT match the auth base domain
|
||||
$request = Request::create('https://other.com/', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
$cookies = $response->headers->getCookies();
|
||||
self::assertCount(1, $cookies);
|
||||
// domain is null when host does not match
|
||||
self::assertNull($cookies[0]->getDomain());
|
||||
// still uses auth cookie name since authBase is set
|
||||
self::assertSame('__Http-Domain-Preauth', $cookies[0]->getName());
|
||||
}
|
||||
|
||||
public function testCheckTokenWithEmptyReturnParameterFallsBackToPath(): void
|
||||
{
|
||||
$manager = $this->makeLoginManager();
|
||||
$payload = $this->makePayloadWithNonce($manager, scope: Scope::Cookie);
|
||||
|
||||
$this->backupCodeManager->method('verifyAndConsume')->willReturn(false);
|
||||
|
||||
// return parameter is present but empty string
|
||||
$request = Request::create('/?return=', 'GET');
|
||||
|
||||
$response = $manager->checkToken($payload, $request);
|
||||
|
||||
self::assertNotNull($response);
|
||||
$location = $response->headers->get('Location');
|
||||
self::assertNotNull($location);
|
||||
// should fall back to path since empty string is not a valid URL
|
||||
self::assertStringStartsWith('/', $location);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Trait;
|
||||
|
||||
use App\Trait\CookieNameTrait;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
|
||||
final class CookieNameTraitTest extends TestCase
|
||||
{
|
||||
use CookieNameTrait;
|
||||
|
||||
public function testCookieName(): void
|
||||
{
|
||||
self::assertSame('__Host-Http-Preauth', $this->cookieName());
|
||||
}
|
||||
|
||||
public function testAuthCookieName(): void
|
||||
{
|
||||
self::assertSame('__Http-Domain-Preauth', $this->authCookieName());
|
||||
}
|
||||
|
||||
public function testHeaderName(): void
|
||||
{
|
||||
self::assertSame('X-Preauth', $this->headerName());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,111 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Trait;
|
||||
|
||||
use App\ConfigBag;
|
||||
use App\Tests\Support\TotpTestHelper;
|
||||
use App\Trait\GetTotpTrait;
|
||||
use OTPHP\TOTPInterface;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
|
||||
final class GetTotpTraitTest extends TestCase
|
||||
{
|
||||
use TotpTestHelper;
|
||||
|
||||
private function makeObject(): object
|
||||
{
|
||||
return new class () {
|
||||
use GetTotpTrait;
|
||||
|
||||
public function publicGetTotp(): TOTPInterface
|
||||
{
|
||||
return $this->getTotp();
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
public function testSetConfigSetsProperty(): void
|
||||
{
|
||||
$obj = $this->makeObject();
|
||||
$config = $this->makeConfig();
|
||||
|
||||
$obj->setConfig($config);
|
||||
|
||||
$reflection = new \ReflectionProperty($obj, 'config');
|
||||
self::assertSame($config, $reflection->getValue($obj));
|
||||
}
|
||||
|
||||
public function testGetTotpReturnsTotpInterface(): void
|
||||
{
|
||||
$obj = $this->makeObject();
|
||||
$obj->setConfig($this->makeConfig());
|
||||
|
||||
$totp = $obj->publicGetTotp();
|
||||
|
||||
self::assertInstanceOf(TOTPInterface::class, $totp);
|
||||
}
|
||||
|
||||
public function testGetTotpReturnsValidCode(): void
|
||||
{
|
||||
$obj = $this->makeObject();
|
||||
$obj->setConfig($this->makeConfig());
|
||||
|
||||
$totp = $obj->publicGetTotp();
|
||||
|
||||
// the code at the frozen time should match our helper
|
||||
self::assertSame($this->validTotpCode(), $totp->now());
|
||||
}
|
||||
|
||||
public function testGetTotpThrowsOnInvalidUri(): void
|
||||
{
|
||||
$obj = $this->makeObject();
|
||||
$clock = $this->frozenClock();
|
||||
$utilities = $this->createUtilities($clock);
|
||||
$config = new ConfigBag(
|
||||
$utilities,
|
||||
$clock,
|
||||
3600,
|
||||
'not-a-valid-uri',
|
||||
0,
|
||||
false,
|
||||
'Error',
|
||||
'Teapot',
|
||||
'Too Many'
|
||||
);
|
||||
$obj->setConfig($config);
|
||||
|
||||
// Factory::loadFromProvisioningUri throws InvalidProvisioningUriException
|
||||
// which is not caught by getTotp() since the instanceof check only runs
|
||||
// after a successful load — so we expect a Throwable here
|
||||
$this->expectException(\Throwable::class);
|
||||
$obj->publicGetTotp();
|
||||
}
|
||||
|
||||
public function testGetTotpThrowsHttpExceptionWhenNotTotpType(): void
|
||||
{
|
||||
// A HOTP URI loads successfully as an OTPInterface but is NOT a TOTPInterface,
|
||||
// so the instanceof check in getTotp() should throw an HttpException(500)
|
||||
$obj = $this->makeObject();
|
||||
$clock = $this->frozenClock();
|
||||
$utilities = $this->createUtilities($clock);
|
||||
$config = new ConfigBag(
|
||||
$utilities,
|
||||
$clock,
|
||||
3600,
|
||||
'otpauth://hotp/Test-HOTP?secret=JBSWY3DPEHPK3PXP&counter=0',
|
||||
0,
|
||||
false,
|
||||
'Error',
|
||||
'Teapot',
|
||||
'Too Many'
|
||||
);
|
||||
$obj->setConfig($config);
|
||||
|
||||
$this->expectException(HttpException::class);
|
||||
$this->expectExceptionMessage('Internal Server Exception');
|
||||
$obj->publicGetTotp();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Trait;
|
||||
|
||||
use App\Trait\HasLoggerTrait;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Log\LoggerInterface;
|
||||
|
||||
final class HasLoggerTraitTest extends TestCase
|
||||
{
|
||||
use HasLoggerTrait;
|
||||
|
||||
public function testSetLogger(): void
|
||||
{
|
||||
$logger = $this->createStub(LoggerInterface::class);
|
||||
$this->setLogger($logger);
|
||||
self::assertSame($logger, $this->logger);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,234 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Trait;
|
||||
|
||||
use App\Trait\MakeNonceTrait;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Cache\CacheItemInterface;
|
||||
use Psr\Cache\CacheItemPoolInterface;
|
||||
use Psr\Log\NullLogger;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
|
||||
/**
|
||||
* Wraps the trait in a concrete class with public proxies so the protected
|
||||
* methods can be exercised from test scope.
|
||||
*/
|
||||
final class MakeNonceTraitTest extends TestCase
|
||||
{
|
||||
private function makeObject(): object
|
||||
{
|
||||
return new class () {
|
||||
use MakeNonceTrait;
|
||||
|
||||
public function publicMakeNonce(int $retries = 3): string
|
||||
{
|
||||
return $this->makeNonce($retries);
|
||||
}
|
||||
|
||||
public function publicMakeCacheKey(string $name): string
|
||||
{
|
||||
return $this->makeCacheKey($name);
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
public function testMakeNonceReturnsBase64UrlString(): void
|
||||
{
|
||||
$obj = $this->makeObject();
|
||||
$obj->setLogger(new NullLogger());
|
||||
$obj->setNonceCache(new ArrayAdapter());
|
||||
|
||||
$nonce = $obj->publicMakeNonce();
|
||||
|
||||
self::assertIsString($nonce);
|
||||
// 15 bytes -> 20 base64 chars without padding
|
||||
self::assertSame(20, strlen($nonce));
|
||||
// base64url charset only
|
||||
self::assertMatchesRegularExpression('/^[A-Za-z0-9_-]+$/', $nonce);
|
||||
}
|
||||
|
||||
public function testMakeNonceStoresNonceInCache(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$obj = $this->makeObject();
|
||||
$obj->setLogger(new NullLogger());
|
||||
$obj->setNonceCache($pool);
|
||||
|
||||
$nonce = $obj->publicMakeNonce();
|
||||
|
||||
// makeNonce stores via makeCacheKey() which rewrites '-' to '_'
|
||||
$key = $obj->publicMakeCacheKey($nonce);
|
||||
self::assertTrue($pool->hasItem($key));
|
||||
$item = $pool->getItem($key);
|
||||
self::assertTrue($item->get());
|
||||
}
|
||||
|
||||
public function testMakeNonceSetsExpiry(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$obj = $this->makeObject();
|
||||
$obj->setLogger(new NullLogger());
|
||||
$obj->setNonceCache($pool);
|
||||
|
||||
$nonce = $obj->publicMakeNonce();
|
||||
|
||||
$item = $pool->getItem($obj->publicMakeCacheKey($nonce));
|
||||
$expiry = $item->getMetadata()['expiry'];
|
||||
// NONCE_TTL is 120 seconds
|
||||
self::assertLessThanOrEqual(120, (int) $expiry - time());
|
||||
self::assertGreaterThan(time(), (int) $expiry);
|
||||
}
|
||||
|
||||
public function testTwoNoncesAreDifferent(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$obj = $this->makeObject();
|
||||
$obj->setLogger(new NullLogger());
|
||||
$obj->setNonceCache($pool);
|
||||
|
||||
$nonce1 = $obj->publicMakeNonce();
|
||||
$nonce2 = $obj->publicMakeNonce();
|
||||
|
||||
self::assertNotSame($nonce1, $nonce2);
|
||||
}
|
||||
|
||||
public function testMakeNonceThrowsAfterMaxRetries(): void
|
||||
{
|
||||
// Create a stub pool that always reports every key as a hit (collision)
|
||||
$pool = $this->createStub(CacheItemPoolInterface::class);
|
||||
$item = $this->createStub(CacheItemInterface::class);
|
||||
$item->method('isHit')->willReturn(true);
|
||||
$item->method('get')->willReturn(true);
|
||||
$pool->method('getItem')->willReturn($item);
|
||||
$pool->method('save')->willReturn(true);
|
||||
|
||||
$obj = $this->makeObject();
|
||||
$obj->setLogger(new NullLogger());
|
||||
$obj->setNonceCache($pool);
|
||||
|
||||
$this->expectException(HttpException::class);
|
||||
$this->expectExceptionMessage('Internal Server Error');
|
||||
|
||||
$obj->publicMakeNonce();
|
||||
}
|
||||
|
||||
public function testMakeNonceRetriesAndSucceedsAfterCollision(): void
|
||||
{
|
||||
// Use a spy pool that returns isHit=true on the first getItem call
|
||||
// (simulating a collision), then delegates to a real ArrayAdapter for
|
||||
// subsequent calls so the retry succeeds.
|
||||
$realPool = new ArrayAdapter();
|
||||
$collisionCount = 0;
|
||||
|
||||
$spyPool = new class ($realPool, $collisionCount) implements CacheItemPoolInterface {
|
||||
private int $hits = 0;
|
||||
public function __construct(
|
||||
private CacheItemPoolInterface $inner,
|
||||
private int &$hitCounter,
|
||||
) {
|
||||
}
|
||||
|
||||
public function getItem(string $key): CacheItemInterface
|
||||
{
|
||||
$item = $this->inner->getItem($key);
|
||||
// pretend the first requested key is already a hit (collision)
|
||||
if ($this->hits === 0) {
|
||||
$this->hits++;
|
||||
$this->hitCounter++;
|
||||
return new class ($key) implements CacheItemInterface {
|
||||
public function __construct(private string $key)
|
||||
{
|
||||
}
|
||||
public function getKey(): string
|
||||
{
|
||||
return $this->key;
|
||||
}
|
||||
public function get(): mixed
|
||||
{
|
||||
return true;
|
||||
}
|
||||
public function isHit(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
public function set(mixed $value): static
|
||||
{
|
||||
return $this;
|
||||
}
|
||||
public function expiresAt(?\DateTimeInterface $expiration): static
|
||||
{
|
||||
return $this;
|
||||
}
|
||||
public function expiresAfter(int|\DateInterval|null $time): static
|
||||
{
|
||||
return $this;
|
||||
}
|
||||
};
|
||||
}
|
||||
return $item;
|
||||
}
|
||||
public function getItems(array $keys = []): iterable
|
||||
{
|
||||
return $this->inner->getItems($keys);
|
||||
}
|
||||
public function hasItem(string $key): bool
|
||||
{
|
||||
return $this->inner->hasItem($key);
|
||||
}
|
||||
public function clear(): bool
|
||||
{
|
||||
return $this->inner->clear();
|
||||
}
|
||||
public function deleteItem(string $key): bool
|
||||
{
|
||||
return $this->inner->deleteItem($key);
|
||||
}
|
||||
public function deleteItems(array $keys): bool
|
||||
{
|
||||
return $this->inner->deleteItems($keys);
|
||||
}
|
||||
public function save(CacheItemInterface $item): bool
|
||||
{
|
||||
return $this->inner->save($item);
|
||||
}
|
||||
public function saveDeferred(CacheItemInterface $item): bool
|
||||
{
|
||||
return $this->inner->saveDeferred($item);
|
||||
}
|
||||
public function commit(): bool
|
||||
{
|
||||
return $this->inner->commit();
|
||||
}
|
||||
};
|
||||
|
||||
$obj = $this->makeObject();
|
||||
$obj->setLogger(new NullLogger());
|
||||
$obj->setNonceCache($spyPool);
|
||||
|
||||
// should retry and succeed on the second attempt
|
||||
$nonce = $obj->publicMakeNonce();
|
||||
self::assertIsString($nonce);
|
||||
self::assertSame(20, strlen($nonce));
|
||||
self::assertSame(1, $collisionCount, 'Expected exactly one collision before success');
|
||||
}
|
||||
|
||||
public function testMakeNonceThrowsImmediatelyWithZeroRetries(): void
|
||||
{
|
||||
$pool = $this->createStub(CacheItemPoolInterface::class);
|
||||
$item = $this->createStub(CacheItemInterface::class);
|
||||
$item->method('isHit')->willReturn(true);
|
||||
$item->method('get')->willReturn(true);
|
||||
$pool->method('getItem')->willReturn($item);
|
||||
$pool->method('save')->willReturn(true);
|
||||
|
||||
$obj = $this->makeObject();
|
||||
$obj->setLogger(new NullLogger());
|
||||
$obj->setNonceCache($pool);
|
||||
|
||||
$this->expectException(HttpException::class);
|
||||
$obj->publicMakeNonce(0);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,70 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit\Trait;
|
||||
|
||||
use App\Trait\StringTrait;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
|
||||
final class StringTraitTest extends TestCase
|
||||
{
|
||||
use StringTrait;
|
||||
|
||||
public function testMakeCacheKeySanitizesInvalidChars(): void
|
||||
{
|
||||
self::assertSame('hello_world', $this->makeCacheKey('hello world'));
|
||||
self::assertSame('hello_world', $this->makeCacheKey('hello!world'));
|
||||
self::assertSame('a_b_c_d', $this->makeCacheKey('a/b@c#d'));
|
||||
}
|
||||
|
||||
public function testMakeCacheKeyPreservesValidChars(): void
|
||||
{
|
||||
self::assertSame('ABC_123.abc', $this->makeCacheKey('ABC_123.abc'));
|
||||
}
|
||||
|
||||
public function testMakeCacheKeyTruncatesLongNames(): void
|
||||
{
|
||||
$long = str_repeat('a', 300);
|
||||
$result = $this->makeCacheKey($long);
|
||||
self::assertSame(128, mb_strlen($result));
|
||||
}
|
||||
|
||||
public function testMakeCacheKeyEmptyString(): void
|
||||
{
|
||||
self::assertSame('', $this->makeCacheKey(''));
|
||||
}
|
||||
|
||||
public function testMakeCacheKeyWithOnlyInvalidChars(): void
|
||||
{
|
||||
// preg_replace with + collapses consecutive invalid chars into one _
|
||||
self::assertSame('_', $this->makeCacheKey('!!!'));
|
||||
self::assertSame('_', $this->makeCacheKey(' '));
|
||||
self::assertSame('_', $this->makeCacheKey('!@#'));
|
||||
self::assertSame('_', $this->makeCacheKey('!@ #'));
|
||||
}
|
||||
|
||||
public function testMakeCacheKeyTruncatesToExactly128(): void
|
||||
{
|
||||
$input = str_repeat('a', 128);
|
||||
self::assertSame(128, mb_strlen($this->makeCacheKey($input)));
|
||||
self::assertSame($input, $this->makeCacheKey($input));
|
||||
|
||||
$input129 = str_repeat('a', 129);
|
||||
self::assertSame(128, mb_strlen($this->makeCacheKey($input129)));
|
||||
}
|
||||
|
||||
public function testMakeCacheKeyWithMultibyteChars(): void
|
||||
{
|
||||
// multibyte chars are replaced with a single underscore
|
||||
$result = $this->makeCacheKey('héllo wörld');
|
||||
// é and ö are not in [A-Za-z0-9_.] so they become _
|
||||
self::assertSame('h_llo_w_rld', $result);
|
||||
}
|
||||
|
||||
public function testMakeCacheKeyWithEmoji(): void
|
||||
{
|
||||
$result = $this->makeCacheKey('a🎉b');
|
||||
self::assertSame('a_b', $result);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,76 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Tests\Unit;
|
||||
|
||||
use App\Utilities;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Psr\Clock\ClockInterface;
|
||||
use Symfony\Component\Cache\Adapter\ArrayAdapter;
|
||||
|
||||
final class UtilitiesTest extends TestCase
|
||||
{
|
||||
private function makeUtilities(?ArrayAdapter $pool = null, ?ClockInterface $clock = null): Utilities
|
||||
{
|
||||
$pool ??= new ArrayAdapter();
|
||||
$clock ??= $this->createStub(ClockInterface::class);
|
||||
return new Utilities($clock, $pool);
|
||||
}
|
||||
|
||||
public function testLoadTotpReturnsCachedValueWhenPresent(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$item = $pool->getItem('totp');
|
||||
$item->set('otpauth://totp/cached?secret=ABCDEFGH');
|
||||
$pool->save($item);
|
||||
|
||||
$utilities = $this->makeUtilities($pool);
|
||||
|
||||
$result = $utilities->loadTotp();
|
||||
|
||||
self::assertSame('otpauth://totp/cached?secret=ABCDEFGH', $result);
|
||||
}
|
||||
|
||||
public function testLoadTotpGeneratesAndStoresWhenMissing(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$utilities = $this->makeUtilities($pool);
|
||||
|
||||
$result = $utilities->loadTotp();
|
||||
|
||||
self::assertNotEmpty($result);
|
||||
self::assertStringStartsWith('otpauth://totp/', $result);
|
||||
|
||||
// stored in cache for next boot
|
||||
$cached = $pool->getItem('totp');
|
||||
self::assertTrue($cached->isHit());
|
||||
self::assertSame($result, $cached->get());
|
||||
}
|
||||
|
||||
public function testLoadTotpSetsFarFutureExpiry(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$utilities = $this->makeUtilities($pool);
|
||||
|
||||
$utilities->loadTotp();
|
||||
|
||||
$cached = $pool->getItem('totp');
|
||||
$expiry = $cached->getMetadata()['expiry'];
|
||||
// 2999-12-31 is well in the future, far beyond any reasonable test timestamp
|
||||
self::assertGreaterThan((new \DateTimeImmutable('+10 years'))->getTimestamp(), (int) $expiry);
|
||||
}
|
||||
|
||||
public function testLoadTotpIsIdempotentAfterGeneration(): void
|
||||
{
|
||||
$pool = new ArrayAdapter();
|
||||
$utilities = $this->makeUtilities($pool);
|
||||
|
||||
$first = $utilities->loadTotp();
|
||||
|
||||
// second call should find it in cache and return the same value
|
||||
$second = $utilities->loadTotp();
|
||||
|
||||
self::assertSame($first, $second);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
<?php
|
||||
|
||||
use Symfony\Component\Dotenv\Dotenv;
|
||||
|
||||
require dirname(__DIR__).'/vendor/autoload.php';
|
||||
|
||||
if (method_exists(Dotenv::class, 'bootEnv')) {
|
||||
(new Dotenv())->bootEnv(dirname(__DIR__).'/.env.test');
|
||||
}
|
||||
|
||||
if (!isset($_SERVER['APP_DEBUG'])) {
|
||||
$_SERVER['APP_DEBUG'] = false;
|
||||
}
|
||||
Reference in New Issue
Block a user