src/Security/AdminFormAuthenticator.php line 63

Open in your IDE?
  1. <?php
  2. namespace App\Security;
  3. use App\Utils\UserUtils;
  4. use Doctrine\ORM\EntityManagerInterface;
  5. use Evo\Infrastructure\MappingORM\User;
  6. use Symfony\Component\HttpFoundation\RedirectResponse;
  7. use Symfony\Component\HttpFoundation\Request;
  8. use Symfony\Component\Routing\Generator\UrlGeneratorInterface;
  9. use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
  10. use Symfony\Component\Security\Core\Encoder\UserPasswordEncoderInterface;
  11. use Symfony\Component\Security\Core\Exception\CustomUserMessageAuthenticationException;
  12. use Symfony\Component\Security\Core\Exception\InvalidCsrfTokenException;
  13. use Symfony\Component\Security\Core\Security;
  14. use Symfony\Component\Security\Core\User\UserInterface;
  15. use Symfony\Component\Security\Core\User\UserProviderInterface;
  16. use Symfony\Component\Security\Csrf\CsrfToken;
  17. use Symfony\Component\Security\Csrf\CsrfTokenManagerInterface;
  18. use Symfony\Component\Security\Guard\Authenticator\AbstractFormLoginAuthenticator;
  19. use Symfony\Component\Security\Http\Util\TargetPathTrait;
  20. class AdminFormAuthenticator extends AbstractFormLoginAuthenticator
  21. {
  22.     use TargetPathTrait;
  23.     private EntityManagerInterface $entityManager;
  24.     private UrlGeneratorInterface $urlGenerator;
  25.     private CsrfTokenManagerInterface $csrfTokenManager;
  26.     private UserUtils $userUtils;
  27.     private UserPasswordEncoderInterface $passwordEncoder;
  28.     public function __construct(
  29.         EntityManagerInterface $entityManager,
  30.         UrlGeneratorInterface $urlGenerator,
  31.         CsrfTokenManagerInterface $csrfTokenManager,
  32.         UserUtils $userUtils,
  33.         UserPasswordEncoderInterface $passwordEncoder
  34.     ) {
  35.         $this->entityManager $entityManager;
  36.         $this->urlGenerator $urlGenerator;
  37.         $this->csrfTokenManager $csrfTokenManager;
  38.         $this->userUtils $userUtils;
  39.         $this->passwordEncoder $passwordEncoder;
  40.     }
  41.     public function supports(Request $request)
  42.     {
  43.         return 'app_admin_login' === $request->attributes->get('_route')
  44.             && $request->isMethod('POST');
  45.     }
  46.     public function getCredentials(Request $request)
  47.     {
  48.         $credentials = [
  49.             'username' => $request->request->get('username'),
  50.             'password' => $request->request->get('password'),
  51.             'csrf_token' => $request->request->get('_csrf_token'),
  52.         ];
  53.         $request->getSession()->set(
  54.             Security::LAST_USERNAME,
  55.             $credentials['username']
  56.         );
  57.         return $credentials;
  58.     }
  59.     public function getUser($credentialsUserProviderInterface $userProvider)
  60.     {
  61.         $token = new CsrfToken('authenticate'$credentials['csrf_token']);
  62.         if (!$this->csrfTokenManager->isTokenValid($token)) {
  63.             throw new InvalidCsrfTokenException();
  64.         }
  65.         $user $this->entityManager->getRepository(User::class)->loadUserByUsername($credentials['username'], true);
  66.         if (!$user) {
  67.             // fail authentication with a custom error
  68.             throw new CustomUserMessageAuthenticationException('Username could not be found.');
  69.         }
  70.         return $user;
  71.     }
  72.     public function checkCredentials($credentialsUserInterface $user)
  73.     {
  74.         return $this->passwordEncoder->isPasswordValid($user$credentials['password']);
  75.     }
  76.     public function onAuthenticationSuccess(Request $requestTokenInterface $token$providerKey)
  77.     {
  78.         /** @var User $user */
  79.         $user $token->getUser();
  80.         $cookieLogout $request->cookies->get('auto_logout');
  81.         if (!isset($cookieLogout)) {
  82.             $code $this->userUtils->generateCodeConfirmation();
  83.             $user->setCodeConfirmation($code);
  84.             $this->entityManager->persist($user);
  85.             $this->entityManager->flush();
  86.             return new RedirectResponse($this->urlGenerator->generate('app_admin_auth_confirmation'));
  87.         }
  88.         $targetPath $this->getTargetPath($request->getSession(), $providerKey);
  89.         if ($this->urlGenerator->generate('app_admin_login') !== $targetPath && !empty($targetPath)) {
  90.             return new RedirectResponse($targetPath);
  91.         }
  92.         return new RedirectResponse($this->urlGenerator->generate('app_admin_dashboard_index'));
  93.     }
  94.     protected function getLoginUrl()
  95.     {
  96.         return $this->urlGenerator->generate('app_admin_login');
  97.     }
  98. }