generated from Nodarx/template
Add WOPI discovery service and connection diagnostics
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace KTXM\ServiceWopi\Discovery;
|
||||
|
||||
use InvalidArgumentException;
|
||||
|
||||
final readonly class ServerAddress
|
||||
{
|
||||
public string $url;
|
||||
public string $origin;
|
||||
|
||||
public function __construct(string $url)
|
||||
{
|
||||
$parts = parse_url($url);
|
||||
if ($parts === false || strtolower($parts['scheme'] ?? '') !== 'https'
|
||||
|| empty($parts['host']) || isset($parts['user']) || isset($parts['pass'])
|
||||
|| isset($parts['query']) || isset($parts['fragment'])
|
||||
|| preg_match('/[\x00-\x20\x7f\\\\]/', $url)
|
||||
|| filter_var($url, FILTER_VALIDATE_URL) === false) {
|
||||
throw new InvalidArgumentException('Use an HTTPS server URL without credentials, query parameters, or a fragment.');
|
||||
}
|
||||
$this->origin = 'https://' . strtolower($parts['host'])
|
||||
. (isset($parts['port']) && $parts['port'] !== 443 ? ':' . $parts['port'] : '');
|
||||
$this->url = $this->origin . rtrim($parts['path'] ?? '', '/');
|
||||
}
|
||||
|
||||
public function discoveryUrl(): string { return $this->url . '/hosting/discovery'; }
|
||||
|
||||
public function assertTrustedAction(string $url): void
|
||||
{
|
||||
$plain = preg_replace('/<[^<>]*>/', '', $url);
|
||||
$parts = parse_url($plain);
|
||||
if ($parts === false || isset($parts['user']) || isset($parts['pass'])
|
||||
|| isset($parts['fragment']) || preg_match('/[\x00-\x20\x7f\\\\<>]/', $plain)
|
||||
|| filter_var($plain, FILTER_VALIDATE_URL) === false) {
|
||||
throw new InvalidArgumentException('Discovery contains an invalid action URL.');
|
||||
}
|
||||
$origin = strtolower($parts['scheme'] ?? '') . '://' . strtolower($parts['host'] ?? '')
|
||||
. (isset($parts['port']) && $parts['port'] !== 443 ? ':' . $parts['port'] : '');
|
||||
if ($origin !== $this->origin) {
|
||||
throw new InvalidArgumentException('Discovery action URL is outside the configured HTTPS server origin.');
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user