Refactor authentication system (#2602)
Make auth configuration available via UI, remove FOSUserBundle and SAML-Bundle dependency
This commit is contained in:
@@ -9,30 +9,32 @@
|
||||
|
||||
namespace App\Configuration;
|
||||
|
||||
class LdapConfiguration
|
||||
final class LdapConfiguration
|
||||
{
|
||||
/**
|
||||
* @var array
|
||||
*/
|
||||
protected $settings = [];
|
||||
private $configuration;
|
||||
|
||||
public function __construct(array $settings)
|
||||
public function __construct(SystemConfiguration $configuration)
|
||||
{
|
||||
$this->settings = $settings;
|
||||
$this->configuration = $configuration;
|
||||
}
|
||||
|
||||
public function isActivated(): bool
|
||||
{
|
||||
return $this->configuration->isLdapActive();
|
||||
}
|
||||
|
||||
public function getRoleParameters(): array
|
||||
{
|
||||
return (array) $this->settings['role'];
|
||||
return $this->configuration->getLdapRoleParameters();
|
||||
}
|
||||
|
||||
public function getUserParameters(): array
|
||||
{
|
||||
return (array) $this->settings['user'];
|
||||
return $this->configuration->getLdapUserParameters();
|
||||
}
|
||||
|
||||
public function getConnectionParameters(): array
|
||||
{
|
||||
return (array) $this->settings['connection'];
|
||||
return $this->configuration->getLdapConnectionParameters();
|
||||
}
|
||||
}
|
||||
|
||||
50
src/Configuration/SamlConfiguration.php
Normal file
50
src/Configuration/SamlConfiguration.php
Normal file
@@ -0,0 +1,50 @@
|
||||
<?php
|
||||
|
||||
/*
|
||||
* This file is part of the Kimai time-tracking app.
|
||||
*
|
||||
* For the full copyright and license information, please view the LICENSE
|
||||
* file that was distributed with this source code.
|
||||
*/
|
||||
|
||||
namespace App\Configuration;
|
||||
|
||||
final class SamlConfiguration
|
||||
{
|
||||
private $configuration;
|
||||
|
||||
public function __construct(SystemConfiguration $configuration)
|
||||
{
|
||||
$this->configuration = $configuration;
|
||||
}
|
||||
|
||||
public function isActivated(): bool
|
||||
{
|
||||
return $this->configuration->isSamlActive();
|
||||
}
|
||||
|
||||
public function getTitle(): string
|
||||
{
|
||||
return $this->configuration->getSamlTitle();
|
||||
}
|
||||
|
||||
public function getAttributeMapping(): array
|
||||
{
|
||||
return $this->configuration->getSamlAttributeMapping();
|
||||
}
|
||||
|
||||
public function getRolesAttribute(): ?string
|
||||
{
|
||||
return $this->configuration->getSamlRolesAttribute();
|
||||
}
|
||||
|
||||
public function getRolesMapping(): array
|
||||
{
|
||||
return $this->configuration->getSamlRolesMapping();
|
||||
}
|
||||
|
||||
public function getConnection(): array
|
||||
{
|
||||
return $this->configuration->getSamlConnection();
|
||||
}
|
||||
}
|
||||
@@ -23,6 +23,42 @@ class SystemConfiguration implements SystemBundleConfiguration
|
||||
return $repository->getConfiguration();
|
||||
}
|
||||
|
||||
// ========== Login form ==========
|
||||
|
||||
public function isLoginFormActive(): bool
|
||||
{
|
||||
if ($this->isLdapActive()) {
|
||||
return true;
|
||||
}
|
||||
|
||||
// if SAML is active, the login form can be deactivated
|
||||
if (!$this->isSamlActive()) {
|
||||
return true;
|
||||
}
|
||||
|
||||
return (bool) $this->find('user.login');
|
||||
}
|
||||
|
||||
public function isSelfRegistrationActive(): bool
|
||||
{
|
||||
return (bool) $this->find('user.registration');
|
||||
}
|
||||
|
||||
public function getPasswordResetTokenLifetime(): int
|
||||
{
|
||||
return (int) $this->find('user.password_reset_token_ttl');
|
||||
}
|
||||
|
||||
public function getPasswordResetRetryLifetime(): int
|
||||
{
|
||||
return (int) $this->find('user.password_reset_retry_ttl');
|
||||
}
|
||||
|
||||
public function isPasswordResetActive(): bool
|
||||
{
|
||||
return (bool) $this->find('user.password_reset');
|
||||
}
|
||||
|
||||
// ========== SAML configurations ==========
|
||||
|
||||
public function isSamlActive(): bool
|
||||
@@ -30,6 +66,53 @@ class SystemConfiguration implements SystemBundleConfiguration
|
||||
return (bool) $this->find('saml.activate');
|
||||
}
|
||||
|
||||
public function getSamlTitle(): string
|
||||
{
|
||||
return (string) $this->find('saml.title');
|
||||
}
|
||||
|
||||
public function getSamlAttributeMapping(): array
|
||||
{
|
||||
return (array) $this->find('saml.mapping');
|
||||
}
|
||||
|
||||
public function getSamlRolesAttribute(): ?string
|
||||
{
|
||||
return (string) $this->find('saml.roles.attribute');
|
||||
}
|
||||
|
||||
public function getSamlRolesMapping(): array
|
||||
{
|
||||
return (array) $this->find('saml.roles.mapping');
|
||||
}
|
||||
|
||||
public function getSamlConnection(): array
|
||||
{
|
||||
return (array) $this->find('saml.connection');
|
||||
}
|
||||
|
||||
// ========== LDAP configurations ==========
|
||||
|
||||
public function isLdapActive(): bool
|
||||
{
|
||||
return (bool) $this->find('ldap.activate');
|
||||
}
|
||||
|
||||
public function getLdapRoleParameters(): array
|
||||
{
|
||||
return (array) $this->find('ldap.role');
|
||||
}
|
||||
|
||||
public function getLdapUserParameters(): array
|
||||
{
|
||||
return (array) $this->find('ldap.user');
|
||||
}
|
||||
|
||||
public function getLdapConnectionParameters(): array
|
||||
{
|
||||
return (array) $this->find('ldap.connection');
|
||||
}
|
||||
|
||||
// ========== Calendar configurations ==========
|
||||
|
||||
public function getCalendarBusinessDays(): array
|
||||
@@ -121,6 +204,7 @@ class SystemConfiguration implements SystemBundleConfiguration
|
||||
return $this->find('defaults.user.language');
|
||||
}
|
||||
|
||||
// TODO this is only used to display the hourly rate in the user profile
|
||||
public function getUserDefaultCurrency(): string
|
||||
{
|
||||
return $this->find('defaults.user.currency');
|
||||
|
||||
Reference in New Issue
Block a user