Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 2
CRAP
0.00% covered (danger)
0.00%
0 / 1
XsrfTokenValidator
0.00% covered (danger)
0.00%
0 / 7
0.00% covered (danger)
0.00%
0 / 2
12
0.00% covered (danger)
0.00%
0 / 1
 evaluate
0.00% covered (danger)
0.00%
0 / 6
0.00% covered (danger)
0.00%
0 / 1
6
 getServiceManager
0.00% covered (danger)
0.00%
0 / 1
0.00% covered (danger)
0.00%
0 / 1
2
1<?php
2
3/**
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; under version 2
7 * of the License (non-upgradable).
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the Free Software
16 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.
17 *
18 * Copyright (c) 2017 (original work) Open Assessment Technologies SA;
19 *
20 */
21
22namespace oat\tao\helpers\form\validators;
23
24use oat\tao\model\security\xsrf\TokenService;
25use oat\oatbox\service\ServiceManager;
26
27/**
28 * Validate a token
29 *
30 * @author Bertrand Chevrier <bertrand@taotesting.com>
31 */
32class XsrfTokenValidator extends \tao_helpers_form_Validator
33{
34    /**
35     * Validate an active XSRF token.
36     *
37     * @param string $values should be the token
38     * @return boolean true only if valid
39     * @throws \common_exception_Unauthorized if the token is not valid
40     */
41    public function evaluate($values)
42    {
43        $tokenService = $this->getServiceManager()->get(TokenService::SERVICE_ID);
44
45        if ($tokenService->checkToken($values)) {
46            $tokenService->revokeToken($values);
47            return true;
48        }
49
50        \common_Logger::e('Attempt to post a form with the incorrect token');
51        throw new \common_exception_Unauthorized('Invalid token ' . $values);
52    }
53
54    protected function getServiceManager()
55    {
56        return ServiceManager::getServiceManager();
57    }
58}