Code Coverage |
||||||||||
Lines |
Functions and Methods |
Classes and Traits |
||||||||
Total | |
0.00% |
0 / 7 |
|
0.00% |
0 / 2 |
CRAP | |
0.00% |
0 / 1 |
XsrfTokenValidator | |
0.00% |
0 / 7 |
|
0.00% |
0 / 2 |
12 | |
0.00% |
0 / 1 |
evaluate | |
0.00% |
0 / 6 |
|
0.00% |
0 / 1 |
6 | |||
getServiceManager | |
0.00% |
0 / 1 |
|
0.00% |
0 / 1 |
2 |
1 | <?php |
2 | |
3 | /** |
4 | * This program is free software; you can redistribute it and/or |
5 | * modify it under the terms of the GNU General Public License |
6 | * as published by the Free Software Foundation; under version 2 |
7 | * of the License (non-upgradable). |
8 | * |
9 | * This program is distributed in the hope that it will be useful, |
10 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
11 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
12 | * GNU General Public License for more details. |
13 | * |
14 | * You should have received a copy of the GNU General Public License |
15 | * along with this program; if not, write to the Free Software |
16 | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. |
17 | * |
18 | * Copyright (c) 2017 (original work) Open Assessment Technologies SA; |
19 | * |
20 | */ |
21 | |
22 | namespace oat\tao\helpers\form\validators; |
23 | |
24 | use oat\tao\model\security\xsrf\TokenService; |
25 | use oat\oatbox\service\ServiceManager; |
26 | |
27 | /** |
28 | * Validate a token |
29 | * |
30 | * @author Bertrand Chevrier <bertrand@taotesting.com> |
31 | */ |
32 | class XsrfTokenValidator extends \tao_helpers_form_Validator |
33 | { |
34 | /** |
35 | * Validate an active XSRF token. |
36 | * |
37 | * @param string $values should be the token |
38 | * @return boolean true only if valid |
39 | * @throws \common_exception_Unauthorized if the token is not valid |
40 | */ |
41 | public function evaluate($values) |
42 | { |
43 | $tokenService = $this->getServiceManager()->get(TokenService::SERVICE_ID); |
44 | |
45 | if ($tokenService->checkToken($values)) { |
46 | $tokenService->revokeToken($values); |
47 | return true; |
48 | } |
49 | |
50 | \common_Logger::e('Attempt to post a form with the incorrect token'); |
51 | throw new \common_exception_Unauthorized('Invalid token ' . $values); |
52 | } |
53 | |
54 | protected function getServiceManager() |
55 | { |
56 | return ServiceManager::getServiceManager(); |
57 | } |
58 | } |