aboutsummaryrefslogtreecommitdiff
path: root/routes/login.php
blob: 2f7327145117ac8c16bc5bbd274e8f6df2d4717f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
<?php

function presentChallenges(
    Psso\Session $session, Psso\Context $context, ?string $message = null
) {
    $challengeTypes = Psso\AuthFlow::nextStep($context);
    if ($challengeTypes === true) {
        // auth finished! all good
        $session->setChallenges(null);
        $session->setIdentity(
            new Psso\Identity($context->user, $context->groups)
        );
        header('Location: /'); //temporary crap for testing
        return;
    }
    if (count($challengeTypes) == 0) {
        throw new RuntimeException('no more challenges available!! auth fail');
    }
    
    // create challenges as indicated by the auth flow
    $challenges = [];
    foreach ($challengeTypes as $type) {
        $c = $type::create($context);
        $challenges[$c->serial] = $c;
    }

    // send challenges to user
    $resp = new Psso\XMLResponse;
    $resp->doc->addAttribute('title', L('login.title'));
    if (isset($message)) {
        $resp->doc->addChild('challenge-message', L($message));
    }
    foreach ($challenges as $challenge) {
        $challenge->addAsHtml($resp->doc);
    }
    $resp->send();

    // and store the challenges (actual instances!) for next request
    $session->setChallenges($challenges);
}

function GET() {
    $session = Psso\Session::get();
    if ($session->getIdentity() !== null) {
        // already logged in
        header('Location: /'); // change this to return continue page
    }
    
    $context = new Psso\Context;
    presentChallenges($session, $context);
}

function POST(array $config) {
    $session = Psso\Session::get();
    
    // we are receiving results of a previous challenge... load it in
    $challenges = $session->getChallenges();
    $answeredChallenge = $challenges[$_POST['challenge']];
    
    // match up the given input responses to their original Inputs
    $inputData = [];
    foreach ($_POST as $name => $value) {
        if ($name == 'challenge') continue;
        $serial = explode('__', $name, 2)[1];
        $input = $answeredChallenge->findInput($serial);
        $inputData[$input->id] = $value;
    }

    // check provided inputs against the challenge, are they correct?
    $providerClass = 'Psso\\AuthProvider\\' . $config['auth']['provider'];
    $provider = new $providerClass($config);
    $result = $answeredChallenge->validate($provider, $inputData);

    // append the new result to the context so the auth flow can see it
    $context = $answeredChallenge->context;
    $context->addResult($result);

    // also set the user in context if we're able to
    if ($result->successful && isset($result->user) && !isset($context->user)) {
        $context->user = $result->user;
    }
    presentChallenges($session, $context, $result->message);
}