0) { $next = 'https://' . $config['site']['cookie-domains'][0] . '/continue' . '?sid=' . urlencode($sid); if (isset($_GET['next'])) { $next .= '&next=' . urlencode($_GET['next']); } return $next; } if (isset($_GET['next']) && Psso\isValidRedirect($_GET['next'], $config)) { return $_GET['next']; } return '/'; } function presentChallenges( array $config, Psso\Session $session, Psso\Context $context, ?string $message = null ) { $challengeTypes = Psso\AuthFlow::nextStep($context); if ($challengeTypes === true) { // auth finished! all good $session->setChallenges(null); $session->setIdentity(Psso\Identity::fromContext($context)); header('Location: ' . nextTarget($config, $session->token)); return; } if (count($challengeTypes) == 0) { throw new RuntimeException('no more challenges available!! auth fail'); } // create challenges as indicated by the auth flow $challenges = []; foreach ($challengeTypes as $type) { $c = $type::create($context); $challenges[$c->serial] = $c; } // send challenges to user $resp = new Psso\XMLResponse; $resp->doc->addAttribute('title', L('login.title')); $resp->doc->addAttribute('kind', 'challenges'); if (isset($message)) { $resp->doc->addChild('challenge-message', L($message)); } foreach ($challenges as $challenge) { $challenge->addAsHtml($resp->doc); } $resp->send(); // and store the challenges (actual instances!) for next request $session->setChallenges($challenges); } function GET(array $config) { $session = Psso\Session::get(); if ($session->getIdentity() !== null) { // already logged in header('Location: /'); // change this to return continue page } $context = new Psso\Context; presentChallenges($config, $session, $context); } function POST(array $config) { $session = Psso\Session::get(); // we are receiving results of a previous challenge... load it in $challenges = $session->getChallenges(); $answeredChallenge = $challenges[$_POST['challenge']]; // match up the given input responses to their original Inputs $inputData = []; foreach ($_POST as $name => $value) { if ($name == 'challenge') continue; $serial = explode('__', $name, 2)[1]; $input = $answeredChallenge->findInput($serial); $inputData[$input->id] = $value; } // check provided inputs against the challenge, are they correct? $providerClass = 'Psso\\AuthProvider\\' . $config['auth']['provider']; $provider = new $providerClass($config); $result = $answeredChallenge->validate($provider, $inputData); // append the new result to the context so the auth flow can see it $context = $answeredChallenge->context; $context->addResult($result); // also set the user and groups in context if we're able to if ($result->successful && isset($result->user) && !isset($context->user)) { $context->user = $result->user; if ($provider instanceof Psso\AuthInterface\Groups) { $context->groups = $provider->userGroups($context->user); } if ($provider instanceof Psso\AuthInterface\UserExtra) { $context->extras['name'] = $provider->userDisplayName($context->user); $context->extras['email'] = $provider->userEmailAddress($context->user); } } presentChallenges($config, $session, $context, $result->message); }