Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
0.00% covered (danger)
0.00%
0 / 42
0.00% covered (danger)
0.00%
0 / 4
CRAP
0.00% covered (danger)
0.00%
0 / 1
UrlParameterSigning
0.00% covered (danger)
0.00%
0 / 42
0.00% covered (danger)
0.00%
0 / 4
650
0.00% covered (danger)
0.00%
0 / 1
 readResponse
0.00% covered (danger)
0.00%
0 / 20
0.00% covered (danger)
0.00%
0 / 1
72
 testData
0.00% covered (danger)
0.00%
0 / 2
0.00% covered (danger)
0.00%
0 / 1
12
 testScopeList
0.00% covered (danger)
0.00%
0 / 10
0.00% covered (danger)
0.00%
0 / 1
56
 testClusterList
0.00% covered (danger)
0.00%
0 / 10
0.00% covered (danger)
0.00%
0 / 1
56
1<?php
2
3/**
4 * @copyright BerlinOnline Stadtportal GmbH & Co. KG
5 **/
6
7declare(strict_types=1);
8
9namespace BO\Zmsadmin;
10
11use BO\Mellon\Validator;
12use BO\Slim\Helper;
13use BO\Slim\Render;
14use BO\Zmsadmin\Exception\BadRequest;
15use BO\Zmsadmin\Exception\NotAllowed;
16use BO\Zmsentities\Department;
17use BO\Zmsentities\Exception\UserAccountAccessRightsFailed;
18use BO\Zmsentities\Helper\Property;
19use Psr\Http\Message\RequestInterface;
20use Psr\Http\Message\ResponseInterface;
21
22/**
23 * returning Signatures for signing requests
24 */
25class UrlParameterSigning extends BaseController
26{
27    /**
28     * @SuppressWarnings(UnusedFormalParameter)
29     * @param \Psr\Http\Message\ServerRequestInterface $request
30     * @return \Psr\Http\Message\ResponseInterface
31     */
32    #[\Override]
33    public function readResponse(
34        RequestInterface $request,
35        ResponseInterface $response,
36        array $args
37    ): \Psr\Http\Message\ResponseInterface {
38        $validator = $request->getAttribute('validator');
39        $data = $validator->getInput()->isJson()->assertValid()->getValue();
40        $this->testData($data);
41
42        $workstation = \App::$http->readGetResult('/workstation/', ['resolveReferences' => 0])->getEntity();
43        $collections = isset($data['parameters']['collections']) ? $data['parameters']['collections'] : [];
44
45        $hasScopeList = (isset($collections['scopelist']) && strlen($collections['scopelist']) > 0);
46        $hasClusterList = (isset($collections['clusterlist']) && strlen($collections['clusterlist']) > 0);
47        $hasValidScopeId = (
48            isset($workstation['scope']['id']) &&
49            !Validator::value($workstation['scope']['id'])->isNumber()->hasFailed()
50        );
51
52        if (($hasScopeList || $hasClusterList) && $hasValidScopeId) {
53            $organisation = \App::$http->readGetResult(
54                '/scope/' . $workstation['scope']['id'] . '/organisation/',
55                ['resolveReferences' => 3]
56            )->getEntity();
57
58            $this->testScopeList($organisation, $collections);
59            $this->testClusterList($organisation, $collections);
60        }
61
62        $data['hmac'] = Helper::hashQueryParameters($data['section'], $data['parameters'], ['collections', 'queue']);
63        return Render::withJson($response, $data);
64    }
65
66    /**
67     * @return void
68     */
69    private function testData($data)
70    {
71        if (!isset($data['section']) || !isset($data['parameters'])) {
72            throw new BadRequest();
73        }
74    }
75
76    /**
77     * @return void
78     */
79    private function testScopeList($organisation, $collections)
80    {
81        $scopeIds = [];
82        foreach ($organisation->departments as $departmentData) {
83            $department = (new Department($departmentData))->withCompleteScopeList();
84            if (Property::__keyExists('scopes', $department)) {
85                foreach ($department['scopes'] as $scope) {
86                    $scopeIds[$scope['id']] = $scope['id'];
87                }
88            }
89        }
90        if (isset($collections['scopelist']) && strlen($collections['scopelist']) > 0) {
91            $requestedIds = explode(',', $collections['scopelist']);
92            if (count(array_diff($requestedIds, $scopeIds)) > 0) {
93                throw new UserAccountAccessRightsFailed();
94            }
95        }
96    }
97
98    /**
99     * @return void
100     */
101    private function testClusterList($organisation, $collections)
102    {
103        $clusterIds = [];
104        foreach ($organisation->departments as $departmentData) {
105            $department = (new Department($departmentData))->withCompleteScopeList();
106            if (Property::__keyExists('clusters', $department)) {
107                foreach ($department['clusters'] as $cluster) {
108                    $clusterIds[$cluster['id']] = $cluster['id'];
109                }
110            }
111        }
112        if (isset($collections['clusterlist']) && strlen($collections['clusterlist']) > 0) {
113            $requestedIds = explode(',', $collections['clusterlist']);
114            if (count(array_diff($requestedIds, $clusterIds)) > 0) {
115                throw new UserAccountAccessRightsFailed();
116            }
117        }
118    }
119}