src/Security/AppCustomAuthenticator.php line 64

Open in your IDE?
  1. <?php
  2. namespace App\Security;
  3. use App\Entity\User;
  4. use Doctrine\ORM\EntityManagerInterface;
  5. use Symfony\Component\HttpFoundation\RedirectResponse;
  6. use Symfony\Component\HttpFoundation\Request;
  7. use Symfony\Component\Routing\Generator\UrlGeneratorInterface;
  8. use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
  9. use Symfony\Component\Security\Core\Encoder\UserPasswordEncoderInterface;
  10. use Symfony\Component\Security\Core\Exception\InvalidCsrfTokenException;
  11. use Symfony\Component\Security\Core\Exception\UsernameNotFoundException;
  12. use Symfony\Component\Security\Core\Security;
  13. use Symfony\Component\Security\Core\User\UserInterface;
  14. use Symfony\Component\Security\Core\User\UserProviderInterface;
  15. use Symfony\Component\Security\Csrf\CsrfToken;
  16. use Symfony\Component\Security\Csrf\CsrfTokenManagerInterface;
  17. use Symfony\Component\Security\Guard\Authenticator\AbstractFormLoginAuthenticator;
  18. use Symfony\Component\Security\Guard\PasswordAuthenticatedInterface;
  19. use Symfony\Component\Security\Http\Util\TargetPathTrait;
  20. class AppCustomAuthenticator extends AbstractFormLoginAuthenticator implements PasswordAuthenticatedInterface
  21. {
  22.     use TargetPathTrait;
  23.     public const LOGIN_ROUTE 'app_login';
  24.     private $entityManager;
  25.     private $urlGenerator;
  26.     private $csrfTokenManager;
  27.     private $passwordEncoder;
  28.     private $mail;
  29.     public function __construct(EntityManagerInterface $entityManagerUrlGeneratorInterface $urlGeneratorCsrfTokenManagerInterface $csrfTokenManagerUserPasswordEncoderInterface $passwordEncoder)
  30.     {
  31.         $this->entityManager $entityManager;
  32.         $this->urlGenerator $urlGenerator;
  33.         $this->csrfTokenManager $csrfTokenManager;
  34.         $this->passwordEncoder $passwordEncoder;
  35.     }
  36.     public function supports(Request $request)
  37.     {
  38.         return self::LOGIN_ROUTE === $request->attributes->get('_route')
  39.             && $request->isMethod('POST');
  40.     }
  41.     public function getCredentials(Request $request)
  42.     {
  43.         $credentials = [
  44.             'email' => $request->request->get('email'),
  45.             'password' => $request->request->get('password'),
  46.             'csrf_token' => $request->request->get('_csrf_token'),
  47.         ];
  48.         $request->getSession()->set(
  49.             Security::LAST_USERNAME,
  50.             $credentials['email']
  51.         );
  52.         return $credentials;
  53.     }
  54.     public function getUser($credentialsUserProviderInterface $userProvider)
  55.     {
  56.         $token = new CsrfToken('authenticate'$credentials['csrf_token']);
  57.         if (!$this->csrfTokenManager->isTokenValid($token)) {
  58.             throw new InvalidCsrfTokenException();
  59.         }
  60.         $user $this->entityManager->getRepository(User::class)->findOneBy(['email' => $credentials['email']]);
  61.         if (!$user) {
  62.             throw new UsernameNotFoundException('Email could not be found.');
  63.         }
  64.         return $user;
  65.     }
  66.     public function checkCredentials($credentialsUserInterface $user)
  67.     {
  68.         return $this->passwordEncoder->isPasswordValid($user$credentials['password']);
  69.     }
  70.     /**
  71.      * Used to upgrade (rehash) the user's password automatically over time.
  72.      */
  73.     public function getPassword($credentials): ?string
  74.     {
  75.         return $credentials['password'];
  76.     }
  77.     public function onAuthenticationSuccess(Request $requestTokenInterface $token$providerKey)
  78.     {
  79.         
  80.         $mail $this->getCredentials($request);
  81.         $user $this->entityManager->getRepository(User::class)->findOneBy(['email' => $mail['email']]);
  82.       
  83.         
  84.         if (in_array('ROLE_ADMIN'$user->getRoles())){
  85.             return new RedirectResponse($this->urlGenerator->generate('app_admin'));
  86.         }elseif (in_array('ROLE_SUPER_ADMIN'$user->getRoles())){
  87.             return new RedirectResponse($this->urlGenerator->generate('app_admin'));
  88.         }elseif (in_array('ROLE_ADMIN_INTFEDERAL'$user->getRoles())){
  89.             return new RedirectResponse($this->urlGenerator->generate('province_admin'));
  90.         }elseif (in_array('ROLE_ADMIN_FEDERAL'$user->getRoles())){
  91.             return new RedirectResponse($this->urlGenerator->generate('federation_admin'));
  92.         }elseif (in_array('ROLE_DEMANDE'$user->getRoles())){
  93.             return new RedirectResponse($this->urlGenerator->generate('demande_user'));
  94.         }else{
  95.             return new RedirectResponse($this->urlGenerator->generate('usermembre_profil'));
  96.         }
  97.         return new RedirectResponse($this->urlGenerator->generate('app_admin'));
  98.         throw new \Exception('TODO: provide a valid redirect inside '.__FILE__);
  99.     }
  100.     protected function getLoginUrl()
  101.     {
  102.         return $this->urlGenerator->generate(self::LOGIN_ROUTE);
  103.     }
  104. }