12 Commits
Author SHA1 Message Date
bence ee7d9623a3 set redirect_after_login in query parameter as well
soko-web/pipeline/head This commit looks good
2024-10-24 22:15:22 +02:00
bence ecec258a64 allow starttls and smtps for mailing 2024-10-19 22:44:51 +02:00
bence 66040d69db use IRouteCollection for HttpResponse
soko-web/pipeline/head This commit looks good
2024-10-18 18:18:13 +02:00
bence fc2de8e1ab do not use $_ENV vars for mail template 2024-10-18 18:05:53 +02:00
bence 6cb90d5ea2 Merge pull request 'implement cors' (#30) from implement-cors into master
soko-web/pipeline/head This commit looks good
Reviewed-on: #30
2024-08-02 02:07:28 +02:00
bence e67afc401b implement cors
soko-web/pipeline/pr-master This commit looks good
2024-08-02 01:42:30 +02:00
bence e59d627080 Merge pull request 'feature/update-to-php81' (#29) from feature/update-to-php81 into master
soko-web/pipeline/head This commit looks good
Reviewed-on: #29
2023-09-27 22:11:05 +02:00
bence 3acca19d49 use new interface of TestCase
soko-web/pipeline/pr-master This commit looks good
2023-09-27 22:05:56 +02:00
bence 2226b88a88 adapt signature of DatabaseSessionHandler::gc to the parent class
soko-web/pipeline/pr-master There was a failure building this commit
2023-09-27 21:46:32 +02:00
bence 8e08b09ae8 generate composer.lock
soko-web/pipeline/pr-master There was a failure building this commit
2023-09-27 21:41:17 +02:00
bence a3bce1f2aa update composer packages 2023-09-27 21:38:59 +02:00
bence a84d3a3976 update to php 8.1 2023-09-27 21:35:44 +02:00
7 changed files with 441 additions and 590 deletions

No files matched your search

+1 -1
View File
@@ -1,4 +1,4 @@
FROM php:7.4.7-cli-buster FROM php:8.1-cli-bookworm
RUN apt-get update && apt-get install -y unzip RUN apt-get update && apt-get install -y unzip
RUN curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer RUN curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer
+3 -3
View File
@@ -5,12 +5,12 @@
"license": "GNU GPL 3.0", "license": "GNU GPL 3.0",
"require": { "require": {
"vlucas/phpdotenv": "^5.5", "vlucas/phpdotenv": "^5.5",
"symfony/console": "^5.4", "symfony/console": "^6.3",
"phpmailer/phpmailer": "^6.8", "phpmailer/phpmailer": "^6.8",
"cocur/slugify": "^4.3" "cocur/slugify": "^4.5"
}, },
"require-dev": { "require-dev": {
"phpunit/phpunit": "^9.6", "phpunit/phpunit": "^10.3",
"phpstan/phpstan": "^1.10" "phpstan/phpstan": "^1.10"
}, },
"autoload": { "autoload": {
Generated
+366 -568
View File
File diff suppressed because it is too large. Load diff
+4 -9
View File
@@ -29,13 +29,6 @@ class Mail
{ {
$this->body = file_get_contents(ROOT . '/mail/' . $template . '.html'); $this->body = file_get_contents(ROOT . '/mail/' . $template . '.html');
$baseParameters = [
'APP_NAME' => $_ENV['APP_NAME'],
'BASE_URL' => $_ENV['APP_URL'],
];
$params = array_merge($baseParameters, $params);
foreach ($params as $key => $param) { foreach ($params as $key => $param) {
$this->body = str_replace('{{' . $key . '}}', $param, $this->body); $this->body = str_replace('{{' . $key . '}}', $param, $this->body);
} }
@@ -51,8 +44,10 @@ class Mail
if (!empty($_ENV['MAIL_HOST'])) { if (!empty($_ENV['MAIL_HOST'])) {
$mailer->Mailer = 'smtp'; $mailer->Mailer = 'smtp';
$mailer->Host = $_ENV['MAIL_HOST']; $mailer->Host = $_ENV['MAIL_HOST'];
$mailer->Port = !empty($_ENV['MAIL_PORT']) ? $_ENV['MAIL_PORT'] : 25; $mailer->Port = !empty($_ENV['MAIL_PORT']) ? $_ENV['MAIL_PORT'] : 587;
$mailer->SMTPSecure = !empty($_ENV['MAIL_SECURE']) ? $_ENV['MAIL_SECURE'] : '';
$secureMaping = ['none' => '', 'starttls' => PHPMailer::ENCRYPTION_STARTTLS, 'smtps' => PHPMailer::ENCRYPTION_SMTPS];
$mailer->SMTPSecure = !empty($_ENV['MAIL_SECURE']) ? $secureMaping[$_ENV['MAIL_SECURE']] : '';
if (!empty($_ENV['MAIL_USER'])) { if (!empty($_ENV['MAIL_USER'])) {
$mailer->SMTPAuth = true; $mailer->SMTPAuth = true;
+62 -4
View File
@@ -6,12 +6,12 @@ use SokoWeb\Interfaces\Response\IRedirect;
use SokoWeb\Interfaces\Response\IContent; use SokoWeb\Interfaces\Response\IContent;
use SokoWeb\Interfaces\Authentication\IAuthenticationRequired; use SokoWeb\Interfaces\Authentication\IAuthenticationRequired;
use SokoWeb\Interfaces\Authorization\ISecured; use SokoWeb\Interfaces\Authorization\ISecured;
use SokoWeb\Interfaces\Routing\IRouteCollection;
use SokoWeb\Interfaces\Database\IConnection; use SokoWeb\Interfaces\Database\IConnection;
use SokoWeb\Interfaces\Request\IRequest; use SokoWeb\Interfaces\Request\IRequest;
use SokoWeb\Response\Redirect; use SokoWeb\Response\Redirect;
use SokoWeb\Response\HtmlContent; use SokoWeb\Response\HtmlContent;
use SokoWeb\Response\JsonContent; use SokoWeb\Response\JsonContent;
use SokoWeb\Routing\RouteCollection;
class HttpResponse class HttpResponse
{ {
@@ -19,7 +19,7 @@ class HttpResponse
private IConnection $dbConnection; private IConnection $dbConnection;
private RouteCollection $routeCollection; private IRouteCollection $routeCollection;
private array $appConfig; private array $appConfig;
@@ -32,7 +32,7 @@ class HttpResponse
public function __construct( public function __construct(
IRequest $request, IRequest $request,
IConnection $dbConnection, IConnection $dbConnection,
RouteCollection $routeCollection, IRouteCollection $routeCollection,
array $appConfig, array $appConfig,
string $requestMethod, string $requestMethod,
string $requestUrl string $requestUrl
@@ -55,6 +55,11 @@ class HttpResponse
public function render(): void public function render(): void
{ {
$this->handleCors();
if ($this->method === 'options') {
return;
}
$match = $this->routeCollection->match($this->method, $this->parsedUrl['path']); $match = $this->routeCollection->match($this->method, $this->parsedUrl['path']);
if ($match === null) { if ($match === null) {
$this->render404(); $this->render404();
@@ -110,10 +115,63 @@ class HttpResponse
} }
} }
private function handleCors(): void
{
$origin = $this->request->header('Origin');
if (!$origin) {
return;
}
if (isset($this->appConfig['cors']['allow_origins'])) {
if (in_array($origin, $this->appConfig['cors']['allow_origins']) || in_array('*', $this->appConfig['cors']['allow_origins'])) {
header("Access-Control-Allow-Origin: {$origin}");
}
}
if (!empty($this->appConfig['cors']['allow_credentials'])) {
header('Access-Control-Allow-Credentials: true');
}
if ($this->method !== 'options') {
return;
}
if (isset($this->appConfig['cors']['allow_headers'])) {
$headers = explode(',', $this->request->header('Access-Control-Request-Headers'));
if (in_array('*', $this->appConfig['cors']['allow_headers'])) {
$allow_headers = $headers;
} else {
$allow_headers = array_intersect($this->appConfig['cors']['allow_headers'], $headers);
}
if (count($allow_headers) > 0) {
header('Access-Control-Allow-Headers: ' . join(', ', $allow_headers));
}
}
if (isset($this->appConfig['cors']['allow_methods'])) {
if (in_array('*', $this->appConfig['cors']['allow_methods'])) {
$allow_methods = ['DELETE', 'GET', 'HEAD', 'OPTIONS', 'PATCH', 'POST', 'PUT'];
} else {
$allow_methods = $this->appConfig['cors']['allow_methods'];
}
if (count($allow_methods) > 0) {
header('Access-Control-Allow-Methods: ' . join(', ', $allow_methods));
}
}
$max_age = $this->appConfig['cors']['max_age'] ?? 600;
header("Access-Control-Max-Age: {$max_age}");
}
private function redirectToLogin(): void private function redirectToLogin(): void
{ {
$this->request->session()->set('redirect_after_login', $this->rawUrl); $this->request->session()->set('redirect_after_login', $this->rawUrl);
$response = new Redirect($this->routeCollection->getRoute($this->appConfig['loginRouteId'])->generateLink(), IRedirect::TEMPORARY); $response = new Redirect(
$this->routeCollection->getRoute($this->appConfig['loginRouteId'])
->generateLink(['redirect_after_login' => urlencode($this->rawUrl)]),
IRedirect::TEMPORARY);
header('Location: ' . $this->getRedirectUrl($response), true, $response->getHttpCode()); header('Location: ' . $this->getRedirectUrl($response), true, $response->getHttpCode());
} }
+2 -2
View File
@@ -86,12 +86,12 @@ class DatabaseSessionHandler implements ISessionHandler
return true; return true;
} }
public function gc($maxlifetime): bool public function gc($maxlifetime): int|false
{ {
// empty on purpose // empty on purpose
// old sessions are deleted by MaintainDatabaseCommand // old sessions are deleted by MaintainDatabaseCommand
return true; return 1;
} }
public function create_sid(): string public function create_sid(): string
+3 -3
View File
@@ -17,7 +17,7 @@ final class GoogleOAuthTest extends TestCase
$redirectUrl = 'http://example.com/oauth'; $redirectUrl = 'http://example.com/oauth';
$requestMock = $this->getMockBuilder(IRequest::class) $requestMock = $this->getMockBuilder(IRequest::class)
->setMethods(['setUrl', 'setMethod', 'setQuery', 'setHeaders', 'send']) ->onlyMethods(['setUrl', 'setMethod', 'setQuery', 'setHeaders', 'send'])
->getMock(); ->getMock();
$googleOAuth = new GoogleOAuth($requestMock); $googleOAuth = new GoogleOAuth($requestMock);
@@ -48,10 +48,10 @@ final class GoogleOAuthTest extends TestCase
$redirectUrl = 'http://example.com/oauth'; $redirectUrl = 'http://example.com/oauth';
$requestMock = $this->getMockBuilder(IRequest::class) $requestMock = $this->getMockBuilder(IRequest::class)
->setMethods(['setUrl', 'setMethod', 'setQuery', 'setHeaders', 'send']) ->onlyMethods(['setUrl', 'setMethod', 'setQuery', 'setHeaders', 'send'])
->getMock(); ->getMock();
$responseMock = $this->getMockBuilder(IResponse::class) $responseMock = $this->getMockBuilder(IResponse::class)
->setMethods(['getBody', 'getHeaders']) ->onlyMethods(['getBody', 'getHeaders'])
->getMock(); ->getMock();
$googleOAuth = new GoogleOAuth($requestMock); $googleOAuth = new GoogleOAuth($requestMock);