Lines
43.37%
36 / 83
Methods
37.50%
3 / 8
Classes
0.00%
0 / 1
| Name | Lines | Methods | CRAP | ||||
|---|---|---|---|---|---|---|---|
| readResponse | 0.00% | 0 / 20 | 0.00% | 0 / 1 | 72 | ||
| testData | 0.00% | 0 / 2 | 0.00% | 0 / 1 | 12 | ||
| testScopeList | 0.00% | 0 / 10 | 0.00% | 0 / 1 | 56 | ||
| testClusterList | 0.00% | 0 / 10 | 0.00% | 0 / 1 | 56 | ||
| [BO\Zmsadmin\BaseController] __invoke | 100.00% | 3 / 3 | 100.00% | 1 / 1 | 1 | ||
| [BO\Zmsadmin\BaseController] getSchemaConstraintList | 100.00% | 8 / 8 | 100.00% | 1 / 1 | 4 | ||
| [BO\Zmsadmin\BaseController] transformValidationErrors | 61.53% | 8 / 13 | 0.00% | 0 / 1 | 15.69 | ||
| [BO\Zmsadmin\BaseController] handleEntityWrite | 100.00% | 17 / 17 | 100.00% | 1 / 1 | 5 | ||
| 25 | class UrlParameterSigning extends BaseController | |
| 26 | { | |
| 27 | /** | |
| 28 | * @SuppressWarnings(UnusedFormalParameter) | |
| 29 | * @param \Psr\Http\Message\ServerRequestInterface $request | |
| 30 | * @return \Psr\Http\Message\ResponseInterface | |
| 31 | */ | |
| 32 | #[\Override] | |
| 33 | public function readResponse( | |
| 34 | RequestInterface $request, | |
| 35 | ResponseInterface $response, | |
| 36 | array $args | |
| 37 | ): \Psr\Http\Message\ResponseInterface { | |
| 38 | $validator = $request->getAttribute('validator'); | |
| 39 | $data = $validator->getInput()->isJson()->assertValid()->getValue(); | |
| 40 | $this->testData($data); | |
| 41 | ||
| 42 | $workstation = \App::$http->readGetResult('/workstation/', ['resolveReferences' => 0])->getEntity(); | |
| 43 | $collections = isset($data['parameters']['collections']) ? $data['parameters']['collections'] : []; | |
| 44 | ||
| 45 | $hasScopeList = (isset($collections['scopelist']) && strlen($collections['scopelist']) > 0); | |
| 46 | $hasClusterList = (isset($collections['clusterlist']) && strlen($collections['clusterlist']) > 0); | |
| 47 | $hasValidScopeId = ( | |
| 48 | isset($workstation['scope']['id']) && | |
| 49 | !Validator::value($workstation['scope']['id'])->isNumber()->hasFailed() | |
| 50 | ); | |
| 51 | ||
| 52 | if (($hasScopeList || $hasClusterList) && $hasValidScopeId) { | |
| 53 | $organisation = \App::$http->readGetResult( | |
| 54 | '/scope/' . $workstation['scope']['id'] . '/organisation/', | |
| 55 | ['resolveReferences' => 3] | |
| 56 | )->getEntity(); | |
| 57 | ||
| 58 | $this->testScopeList($organisation, $collections); | |
| 59 | $this->testClusterList($organisation, $collections); | |
| 60 | } | |
| 61 | ||
| 62 | $data['hmac'] = Helper::hashQueryParameters($data['section'], $data['parameters'], ['collections', 'queue']); | |
| 63 | return Render::withJson($response, $data); | |
| 64 | } | |
| 65 | ||
| 66 | /** | |
| 67 | * @return void | |
| 68 | */ | |
| 69 | private function testData($data) | |
| 70 | { | |
| 71 | if (!isset($data['section']) || !isset($data['parameters'])) { | |
| 72 | throw new BadRequest(); | |
| 73 | } | |
| 74 | } | |
| 75 | ||
| 76 | /** | |
| 77 | * @return void | |
| 78 | */ | |
| 79 | private function testScopeList($organisation, $collections) | |
| 80 | { | |
| 81 | $scopeIds = []; | |
| 82 | foreach ($organisation->departments as $departmentData) { | |
| 83 | $department = (new Department($departmentData))->withCompleteScopeList(); | |
| 84 | if (Property::__keyExists('scopes', $department)) { | |
| 85 | foreach ($department['scopes'] as $scope) { | |
| 86 | $scopeIds[$scope['id']] = $scope['id']; | |
| 87 | } | |
| 88 | } | |
| 89 | } | |
| 90 | if (isset($collections['scopelist']) && strlen($collections['scopelist']) > 0) { | |
| 91 | $requestedIds = explode(',', $collections['scopelist']); | |
| 92 | if (count(array_diff($requestedIds, $scopeIds)) > 0) { | |
| 93 | throw new UserAccountAccessRightsFailed(); | |
| 94 | } | |
| 95 | } | |
| 96 | } | |
| 97 | ||
| 98 | /** | |
| 99 | * @return void | |
| 100 | */ | |
| 101 | private function testClusterList($organisation, $collections) | |
| 102 | { | |
| 103 | $clusterIds = []; | |
| 104 | foreach ($organisation->departments as $departmentData) { | |
| 105 | $department = (new Department($departmentData))->withCompleteScopeList(); | |
| 106 | if (Property::__keyExists('clusters', $department)) { | |
| 107 | foreach ($department['clusters'] as $cluster) { | |
| 108 | $clusterIds[$cluster['id']] = $cluster['id']; | |
| 109 | } | |
| 110 | } | |
| 111 | } | |
| 112 | if (isset($collections['clusterlist']) && strlen($collections['clusterlist']) > 0) { | |
| 113 | $requestedIds = explode(',', $collections['clusterlist']); | |
| 114 | if (count(array_diff($requestedIds, $clusterIds)) > 0) { | |
| 115 | throw new UserAccountAccessRightsFailed(); | |
| 116 | } | |
| 117 | } | |
| 118 | } | |
| 119 | } |
Inherited from BO\Zmsadmin\BaseController
| 21 | public function __invoke(RequestInterface $request, ResponseInterface $response, array $args) | |
| 22 | { | |
| 23 | $request = $this->initRequest($request); | |
| 24 | $noCacheResponse = \BO\Slim\Render::withLastModified($response, time(), '0'); | |
| 25 | return $this->readResponse($request, $noCacheResponse, $args); | |
| 26 | } |
| 41 | public function getSchemaConstraintList($schema): array | |
| 42 | { | |
| 43 | $list = []; | |
| 44 | $locale = \App::$language->getLocale(); | |
| 45 | foreach ($schema->properties as $key => $property) { | |
| 46 | if (isset($property['x-locale'])) { | |
| 47 | $constraints = $property['x-locale'][$locale]; | |
| 48 | if ($constraints) { | |
| 49 | $list[$key]['description'] = $constraints['messages']; | |
| 50 | } | |
| 51 | } | |
| 52 | } | |
| 53 | return $list; | |
| 54 | } |
| 65 | protected function transformValidationErrors($errorData) | |
| 66 | { | |
| 67 | if (!is_array($errorData) && !($errorData instanceof \Traversable)) { | |
| 68 | return []; | |
| 69 | } | |
| 70 | $transformed = []; | |
| 71 | foreach ($errorData as $pointer => $item) { | |
| 72 | // Extract field name from JSON pointer (e.g., "/id" -> "id", "/contact/email" -> "contact/email") | |
| 73 | // If the key doesn't start with "/", it's already a field name, so use it as-is | |
| 74 | $fieldName = (strpos($pointer, '/') === 0) ? ltrim($pointer, '/') : $pointer; | |
| 75 | // Handle root level errors | |
| 76 | if ($fieldName === '' || $fieldName === null) { | |
| 77 | $fieldName = '_root'; | |
| 78 | } | |
| 79 | // Ensure the item structure is correct (has 'messages' array) | |
| 80 | if (is_array($item) && isset($item['messages'])) { | |
| 81 | $transformed[$fieldName] = $item; | |
| 82 | } elseif (is_array($item)) { | |
| 83 | // If item is an array but doesn't have 'messages', wrap it | |
| 84 | $transformed[$fieldName] = $item; | |
| 85 | } else { | |
| 86 | $transformed[$fieldName] = $item; | |
| 87 | } | |
| 88 | } | |
| 89 | return $transformed; | |
| 90 | } |
| 99 | protected function handleEntityWrite(callable $httpCall) | |
| 100 | { | |
| 101 | try { | |
| 102 | return $httpCall(); | |
| 103 | } catch (\BO\Zmsclient\Exception $exception) { | |
| 104 | if ('BO\Zmsentities\Exception\SchemaValidation' == $exception->template) { | |
| 105 | return [ | |
| 106 | 'template' => 'exception/bo/zmsentities/exception/schemavalidation.twig', | |
| 107 | 'include' => true, | |
| 108 | 'data' => $this->transformValidationErrors($exception->data) | |
| 109 | ]; | |
| 110 | } | |
| 111 | ||
| 112 | $template = TwigExceptionHandler::getExceptionTemplate($exception); | |
| 113 | if ( | |
| 114 | '' != $exception->template | |
| 115 | && \App::$slim->getContainer()->get('view')->getLoader()->exists($template) | |
| 116 | ) { | |
| 117 | return [ | |
| 118 | 'template' => $template, | |
| 119 | 'include' => true, | |
| 120 | 'data' => $this->transformValidationErrors($exception->data) | |
| 121 | ]; | |
| 122 | } | |
| 123 | ||
| 124 | throw $exception; | |
| 125 | } | |
| 126 | } |