blob: 2f7327145117ac8c16bc5bbd274e8f6df2d4717f (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
|
<?php
function presentChallenges(
Psso\Session $session, Psso\Context $context, ?string $message = null
) {
$challengeTypes = Psso\AuthFlow::nextStep($context);
if ($challengeTypes === true) {
// auth finished! all good
$session->setChallenges(null);
$session->setIdentity(
new Psso\Identity($context->user, $context->groups)
);
header('Location: /'); //temporary crap for testing
return;
}
if (count($challengeTypes) == 0) {
throw new RuntimeException('no more challenges available!! auth fail');
}
// create challenges as indicated by the auth flow
$challenges = [];
foreach ($challengeTypes as $type) {
$c = $type::create($context);
$challenges[$c->serial] = $c;
}
// send challenges to user
$resp = new Psso\XMLResponse;
$resp->doc->addAttribute('title', L('login.title'));
if (isset($message)) {
$resp->doc->addChild('challenge-message', L($message));
}
foreach ($challenges as $challenge) {
$challenge->addAsHtml($resp->doc);
}
$resp->send();
// and store the challenges (actual instances!) for next request
$session->setChallenges($challenges);
}
function GET() {
$session = Psso\Session::get();
if ($session->getIdentity() !== null) {
// already logged in
header('Location: /'); // change this to return continue page
}
$context = new Psso\Context;
presentChallenges($session, $context);
}
function POST(array $config) {
$session = Psso\Session::get();
// we are receiving results of a previous challenge... load it in
$challenges = $session->getChallenges();
$answeredChallenge = $challenges[$_POST['challenge']];
// match up the given input responses to their original Inputs
$inputData = [];
foreach ($_POST as $name => $value) {
if ($name == 'challenge') continue;
$serial = explode('__', $name, 2)[1];
$input = $answeredChallenge->findInput($serial);
$inputData[$input->id] = $value;
}
// check provided inputs against the challenge, are they correct?
$providerClass = 'Psso\\AuthProvider\\' . $config['auth']['provider'];
$provider = new $providerClass($config);
$result = $answeredChallenge->validate($provider, $inputData);
// append the new result to the context so the auth flow can see it
$context = $answeredChallenge->context;
$context->addResult($result);
// also set the user in context if we're able to
if ($result->successful && isset($result->user) && !isset($context->user)) {
$context->user = $result->user;
}
presentChallenges($session, $context, $result->message);
}
|