refactor: migrate to scoped execution contexts
Signed-off-by: Sebastian Krupinski <krupinski01@gmail.com>
This commit is contained in:
@@ -4,8 +4,8 @@ namespace KTXM\AuthenticationProviderPassword\Controllers;
|
|||||||
|
|
||||||
use KTXC\Http\Response\JsonResponse;
|
use KTXC\Http\Response\JsonResponse;
|
||||||
use KTXC\Service\UserAccountsService;
|
use KTXC\Service\UserAccountsService;
|
||||||
use KTXC\SessionIdentity;
|
use KTXC\Context\IdentityContextInterface;
|
||||||
use KTXC\SessionTenant;
|
use KTXC\Context\TenantContextInterface;
|
||||||
use KTXF\Controller\ControllerAbstract;
|
use KTXF\Controller\ControllerAbstract;
|
||||||
use KTXF\Routing\Attributes\AuthenticatedRoute;
|
use KTXF\Routing\Attributes\AuthenticatedRoute;
|
||||||
use KTXF\Security\Crypto;
|
use KTXF\Security\Crypto;
|
||||||
@@ -15,8 +15,8 @@ use KTXM\AuthenticationProviderPassword\Stores\CredentialStore;
|
|||||||
class PasswordController extends ControllerAbstract
|
class PasswordController extends ControllerAbstract
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly SessionIdentity $sessionIdentity,
|
private readonly IdentityContextInterface $identityContext,
|
||||||
private readonly SessionTenant $sessionTenant,
|
private readonly TenantContextInterface $tenantContext,
|
||||||
private readonly CredentialStore $credentialStore,
|
private readonly CredentialStore $credentialStore,
|
||||||
private readonly Provider $provider,
|
private readonly Provider $provider,
|
||||||
private readonly Crypto $crypto,
|
private readonly Crypto $crypto,
|
||||||
@@ -27,8 +27,8 @@ class PasswordController extends ControllerAbstract
|
|||||||
#[AuthenticatedRoute('/password/update', name: 'password.update', methods: ['POST'])]
|
#[AuthenticatedRoute('/password/update', name: 'password.update', methods: ['POST'])]
|
||||||
public function update(string $current_password, string $new_password): JsonResponse
|
public function update(string $current_password, string $new_password): JsonResponse
|
||||||
{
|
{
|
||||||
$tenantId = $this->sessionTenant->identifier();
|
$tenantId = $this->tenantContext->identifier();
|
||||||
$identifier = $this->sessionIdentity->mailAddress();
|
$identifier = $this->identityContext->mailAddress();
|
||||||
|
|
||||||
if ($tenantId === null || $identifier === null) {
|
if ($tenantId === null || $identifier === null) {
|
||||||
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
||||||
@@ -56,7 +56,7 @@ class PasswordController extends ControllerAbstract
|
|||||||
#[AuthenticatedRoute('/status', name: 'password.admin.status', methods: ['POST'], permissions: ['authentication_provider_password.admin.view', 'authentication_provider_password.admin.manage'])]
|
#[AuthenticatedRoute('/status', name: 'password.admin.status', methods: ['POST'], permissions: ['authentication_provider_password.admin.view', 'authentication_provider_password.admin.manage'])]
|
||||||
public function getStatus(string $uid): JsonResponse
|
public function getStatus(string $uid): JsonResponse
|
||||||
{
|
{
|
||||||
$tenantId = $this->sessionTenant->identifier();
|
$tenantId = $this->tenantContext->identifier();
|
||||||
|
|
||||||
if ($tenantId === null) {
|
if ($tenantId === null) {
|
||||||
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
||||||
@@ -82,7 +82,7 @@ class PasswordController extends ControllerAbstract
|
|||||||
#[AuthenticatedRoute('/reset', name: 'password.admin.reset', methods: ['POST'], permissions: ['authentication_provider_password.admin.manage'])]
|
#[AuthenticatedRoute('/reset', name: 'password.admin.reset', methods: ['POST'], permissions: ['authentication_provider_password.admin.manage'])]
|
||||||
public function adminReset(string $uid, string $password): JsonResponse
|
public function adminReset(string $uid, string $password): JsonResponse
|
||||||
{
|
{
|
||||||
$tenantId = $this->sessionTenant->identifier();
|
$tenantId = $this->tenantContext->identifier();
|
||||||
|
|
||||||
if ($tenantId === null) {
|
if ($tenantId === null) {
|
||||||
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
||||||
@@ -113,7 +113,7 @@ class PasswordController extends ControllerAbstract
|
|||||||
#[AuthenticatedRoute('/remove', name: 'password.admin.remove', methods: ['POST'], permissions: ['authentication_provider_password.admin.manage'])]
|
#[AuthenticatedRoute('/remove', name: 'password.admin.remove', methods: ['POST'], permissions: ['authentication_provider_password.admin.manage'])]
|
||||||
public function adminRemove(string $uid): JsonResponse
|
public function adminRemove(string $uid): JsonResponse
|
||||||
{
|
{
|
||||||
$tenantId = $this->sessionTenant->identifier();
|
$tenantId = $this->tenantContext->identifier();
|
||||||
|
|
||||||
if ($tenantId === null) {
|
if ($tenantId === null) {
|
||||||
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
return new JsonResponse(['error' => 'Invalid session state'], 400);
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ namespace KTXT\AuthenticationProviderPassword\Tests\Integration;
|
|||||||
|
|
||||||
use KTXC\Http\Request\Request;
|
use KTXC\Http\Request\Request;
|
||||||
use KTXC\Http\Response\Response;
|
use KTXC\Http\Response\Response;
|
||||||
use KTXC\Server;
|
use KTXC\Application;
|
||||||
use KTXC\Stores\UserRolesStore;
|
use KTXC\Stores\UserRolesStore;
|
||||||
use PHPUnit\Framework\TestCase;
|
use PHPUnit\Framework\TestCase;
|
||||||
|
|
||||||
@@ -19,11 +19,11 @@ use PHPUnit\Framework\TestCase;
|
|||||||
* through the real HTTP kernel (routing, tenant resolution, auth middleware,
|
* through the real HTTP kernel (routing, tenant resolution, auth middleware,
|
||||||
* controller), not by calling controllers directly.
|
* controller), not by calling controllers directly.
|
||||||
*
|
*
|
||||||
* A fresh Server (and DI container) is built for every request() call,
|
* A fresh Application (and DI container) is built for every request() call,
|
||||||
* mirroring the one-process-per-request model this app is actually
|
* mirroring the one-process-per-request model this app is actually
|
||||||
* deployed under. Session identity is a container-lifetime singleton that
|
* deployed under. Session identity is a container-lifetime singleton that
|
||||||
* AuthenticationMiddleware only ever sets, never clears, so reusing one
|
* AuthenticationMiddleware only ever sets, never clears, so reusing one
|
||||||
* Server across requests would leak an authenticated identity from one
|
* Application across requests would leak an authenticated identity from one
|
||||||
* "request" into the next — a problem that can't occur in production,
|
* "request" into the next — a problem that can't occur in production,
|
||||||
* where each request gets its own process, but very much can here.
|
* where each request gets its own process, but very much can here.
|
||||||
*
|
*
|
||||||
@@ -37,7 +37,7 @@ abstract class IntegrationTestCase extends TestCase
|
|||||||
|
|
||||||
public static function setUpBeforeClass(): void
|
public static function setUpBeforeClass(): void
|
||||||
{
|
{
|
||||||
if (static::buildServer()->environment() === 'prod') {
|
if (static::buildApplication()->environment() === 'prod') {
|
||||||
self::fail('Refusing to run integration tests against a server configured for the "prod" environment.');
|
self::fail('Refusing to run integration tests against a server configured for the "prod" environment.');
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -58,9 +58,9 @@ abstract class IntegrationTestCase extends TestCase
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
protected static function buildServer(): Server
|
protected static function buildApplication(): Application
|
||||||
{
|
{
|
||||||
return new Server(SERVER_ROOT);
|
return Application::create(SERVER_ROOT);
|
||||||
}
|
}
|
||||||
|
|
||||||
// =========================================================================
|
// =========================================================================
|
||||||
@@ -103,17 +103,16 @@ abstract class IntegrationTestCase extends TestCase
|
|||||||
*/
|
*/
|
||||||
protected static function createRoleWithPermissions(array $permissions, string $label = 'Test Role'): string
|
protected static function createRoleWithPermissions(array $permissions, string $label = 'Test Role'): string
|
||||||
{
|
{
|
||||||
$server = static::buildServer();
|
$application = static::buildApplication();
|
||||||
try {
|
try {
|
||||||
$server->kernel()->boot();
|
$application->kernel()->boot();
|
||||||
$store = $server->container()->get(UserRolesStore::class);
|
$store = $application->container()->get(UserRolesStore::class);
|
||||||
$role = $store->createRole(static::$tenantIdentifier, [
|
$role = $store->createRole(static::$tenantIdentifier, [
|
||||||
'label' => $label,
|
'label' => $label,
|
||||||
'permissions' => $permissions,
|
'permissions' => $permissions,
|
||||||
]);
|
]);
|
||||||
} finally {
|
} finally {
|
||||||
restore_error_handler();
|
$application->shutdown();
|
||||||
restore_exception_handler();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return $role['rid'];
|
return $role['rid'];
|
||||||
@@ -174,15 +173,13 @@ abstract class IntegrationTestCase extends TestCase
|
|||||||
$uri = 'http://' . static::$tenantDomain . $path;
|
$uri = 'http://' . static::$tenantDomain . $path;
|
||||||
$request = Request::create($uri, $method, [], [], [], $server, $content);
|
$request = Request::create($uri, $method, [], [], [], $server, $content);
|
||||||
|
|
||||||
// Kernel::boot() registers a global error/exception handler per
|
// A fresh application mirrors production while shutdown restores its
|
||||||
// instance and never removes it (fine under one-process-per-request
|
// process-level error handler after the in-process request.
|
||||||
// in production; here it would otherwise stack a handler per test).
|
$application = static::buildApplication();
|
||||||
// Pop back to whatever was in place before this request.
|
|
||||||
try {
|
try {
|
||||||
$response = static::buildServer()->handle($request);
|
$response = $application->handleHttp($request);
|
||||||
} finally {
|
} finally {
|
||||||
restore_error_handler();
|
$application->shutdown();
|
||||||
restore_exception_handler();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
$body = $response->getContent();
|
$body = $response->getContent();
|
||||||
|
|||||||
Reference in New Issue
Block a user