src/Security/LoginAuthenticator.php line 62

  1. <?php
  2. namespace App\Security;
  3. use App\Entity\User;
  4. use Exception;
  5. use GuzzleHttp\Client;
  6. use GuzzleHttp\Exception\GuzzleException;
  7. use Psr\Log\LoggerInterface;
  8. use Symfony\Component\DependencyInjection\ParameterBag\ParameterBagInterface;
  9. use Symfony\Component\HttpFoundation\RedirectResponse;
  10. use Symfony\Component\HttpFoundation\Request;
  11. use Symfony\Component\HttpFoundation\Response;
  12. use Symfony\Component\Routing\RouterInterface;
  13. use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
  14. use Symfony\Component\Security\Core\Exception\AuthenticationException;
  15. use Symfony\Component\Security\Core\Exception\CustomUserMessageAuthenticationException;
  16. use Symfony\Component\Security\Http\Authenticator\AbstractAuthenticator;
  17. use Symfony\Component\Security\Http\Authenticator\Passport\Badge\PreAuthenticatedUserBadge;
  18. use Symfony\Component\Security\Http\Authenticator\Passport\Badge\UserBadge;
  19. use Symfony\Component\Security\Http\Authenticator\Passport\Passport;
  20. use Symfony\Component\Security\Http\Authenticator\Passport\SelfValidatingPassport;
  21. use Symfony\Component\Security\Http\SecurityRequestAttributes;
  22. class LoginAuthenticator extends AbstractAuthenticator
  23. {
  24.     public function __construct(private readonly ParameterBagInterface $parameterBag, private readonly LoggerInterface $logger, private readonly RouterInterface $router)
  25.     {
  26.     }
  27.     public function supports(Request $request): ?bool
  28.     {
  29.         return 'login' === $request->attributes->get('_route') || 'index' === $request->attributes->get('_route')
  30.             && $request->isMethod('POST');
  31.     }
  32.     /**
  33.      * @throws GuzzleException
  34.      */
  35.     public function authenticate(Request $request): Passport
  36.     {
  37.         $username $request->request->get('username');
  38.         $password $request->request->get('password');
  39.         $request->getSession()->set(SecurityRequestAttributes::LAST_USERNAME$username);
  40.         $client = new Client(['base_uri' => $this->parameterBag->get('api_url')]);
  41.         $apiToken null;
  42.         try {
  43.             $response $client->post('/login', [
  44.                 'json' => [
  45.                     'username' => $username,
  46.                     'password' => $password
  47.                 ]
  48.             ]);
  49.             $apiToken json_decode($response->getBody()->getContents());
  50.         } catch (Exception $exception) {
  51.             $this->logger->error($exception->getMessage());
  52.             throw new CustomUserMessageAuthenticationException($exception->getMessage());
  53.         }
  54.         return new SelfValidatingPassport(new UserBadge($apiToken->token), [new PreAuthenticatedUserBadge()]);
  55.     }
  56.     public function onAuthenticationSuccess(Request $requestTokenInterface $tokenstring $firewallName): ?Response
  57.     {
  58.         /** @var User $user */
  59.         $user $token->getUser();
  60.         if (in_array(User::ROLE_CONTRACTOR$user->getRoles())) {
  61.             $request->attributes->set(SecurityRequestAttributes::AUTHENTICATION_ERROR, new AuthenticationException('You don\'t have the right access for the admin side'));
  62.             return null;
  63.         }
  64.         if ($user->getPasswordToken()) {
  65.             $request->attributes->set(SecurityRequestAttributes::AUTHENTICATION_ERROR, new AuthenticationException('You have requested a password rest'));
  66.             return null;
  67.         }
  68.         return new RedirectResponse($this->router->generate('app_homepage'));
  69.     }
  70.     public function onAuthenticationFailure(Request $requestAuthenticationException $exception): ?Response
  71.     {
  72.         if ($request->request->count() > 1) {
  73.             $request->attributes->set(SecurityRequestAttributes::AUTHENTICATION_ERROR, new AuthenticationException('The username or password you’ve entered doesn’t match any account information we have on record. Please try again.'));
  74.         }
  75.         return null;
  76.     }
  77. }