RunAsManager.php 2.2KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879
  1. <?php
  2. /*
  3. * Copyright 2010 Johannes M. Schmitt <schmittjoh@gmail.com>
  4. *
  5. * Licensed under the Apache License, Version 2.0 (the "License");
  6. * you may not use this file except in compliance with the License.
  7. * You may obtain a copy of the License at
  8. *
  9. * http://www.apache.org/licenses/LICENSE-2.0
  10. *
  11. * Unless required by applicable law or agreed to in writing, software
  12. * distributed under the License is distributed on an "AS IS" BASIS,
  13. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. * See the License for the specific language governing permissions and
  15. * limitations under the License.
  16. */
  17. namespace JMS\SecurityExtraBundle\Security\Authorization;
  18. use JMS\SecurityExtraBundle\Security\Authentication\Token\RunAsUserToken;
  19. use Symfony\Component\Security\Core\Role\Role;
  20. use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
  21. /**
  22. * The RunAsManager creates throw-away Tokens which are temporarily injected into
  23. * the security context for the duration of the invocation of a specific method.
  24. *
  25. * @author Johannes M. Schmitt <schmittjoh@gmail.com>
  26. */
  27. class RunAsManager implements RunAsManagerInterface
  28. {
  29. private $key;
  30. private $rolePrefix;
  31. public function __construct($key, $rolePrefix = 'ROLE_')
  32. {
  33. $this->key = $key;
  34. $this->rolePrefix = $rolePrefix;
  35. }
  36. /**
  37. * {@inheritDoc}
  38. */
  39. public function buildRunAs(TokenInterface $token, $secureObject, array $attributes)
  40. {
  41. $roles = array();
  42. foreach ($attributes as $attribute)
  43. {
  44. if ($this->supportsAttribute($attribute)) {
  45. $roles[] = new Role($attribute);
  46. }
  47. }
  48. if (0 === count($roles)) {
  49. return null;
  50. }
  51. $roles = array_merge($roles, $token->getRoles());
  52. return new RunAsUserToken($this->key, $token->getUser(), $token->getCredentials(), $roles, $token);
  53. }
  54. /**
  55. * {@inheritDoc}
  56. */
  57. public function supportsAttribute($attribute)
  58. {
  59. return !empty($attribute) && 0 === strpos($attribute, $this->rolePrefix);
  60. }
  61. /**
  62. * {@inheritDoc}
  63. */
  64. public function supportsClass($className)
  65. {
  66. return true;
  67. }
  68. }