-
-
Notifications
You must be signed in to change notification settings - Fork 4
/
Copy pathQueryParameterHandler.php
96 lines (84 loc) · 2.56 KB
/
QueryParameterHandler.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
<?php
namespace romanzipp\Blockade\Handlers;
use Illuminate\Http\Request;
use romanzipp\Blockade\Concerns\ValidatesPassword;
use romanzipp\Blockade\Handlers\Contracts\HandlerContract;
use Spatie\Url\Url;
use Symfony\Component\HttpFoundation\Response as SymfonyResponse;
class QueryParameterHandler extends AbstractHandler implements HandlerContract
{
use ValidatesPassword;
/**
* Check if the current request is already authenticated.
*
* @param \Illuminate\Http\Request $request
*
* @return bool
*/
public function isAuthenticated(Request $request): bool
{
if ( ! $hash = $this->store->getHash($request)) {
return false;
}
return $this->hashMatchesConfigured($hash);
}
/**
* Check if the current request is attempting authentication.
*
* @param \Illuminate\Http\Request $request
*
* @return bool
*/
public function requestAttemptsAuthentication(Request $request): bool
{
return $request->filled(config('blockade.handlers.query.parameter'))
&& $request->isMethod('GET');
}
/**
* Attempt the blockade authentication.
*
* @param \Illuminate\Http\Request $request
*
* @return bool
*/
public function attemptAuthentication(Request $request): bool
{
$password = $request->query(
config('blockade.handlers.query.parameter')
);
if (empty($password)) {
return false;
}
return $this->passwordMatchesConfigured($password);
}
/**
* Store the successful authentication state and return a response.
*
* @param \Illuminate\Http\Request $request
* @param \Closure $next
*
* @return \Symfony\Component\HttpFoundation\Response
*/
public function getSuccessResponse(Request $request, \Closure $next): SymfonyResponse
{
$response = redirect(
Url::fromString($request->fullUrl())
->withoutQueryParameter(
config('blockade.handlers.query.parameter')
)
);
return $this->store->storeSuccessState($request, $response);
}
/**
* Get the response for failed or missing authentication.
*
* @param \Illuminate\Http\Request $request
* @param array<string, mixed> $data
*
* @return \Symfony\Component\HttpFoundation\Response
*/
public function getFailedResponse(Request $request, array $data = []): SymfonyResponse
{
return $this->displayView($request, 'blockade::denied', $data);
}
}