78 lines
2.4 KiB
PHP
78 lines
2.4 KiB
PHP
<?php
|
|
/**
|
|
* Created by IntelliJ IDEA.
|
|
* User: rocho
|
|
* Date: 2018.08.29.
|
|
* Time: 21:58
|
|
*/
|
|
|
|
namespace customerapi\controllers;
|
|
|
|
use customerapi\models\LoginForm;
|
|
use sizeg\jwt\Jwt;
|
|
use sizeg\jwt\JwtHttpBearerAuth;
|
|
use Yii;
|
|
use yii\rest\Controller;
|
|
use yii\web\UnauthorizedHttpException;
|
|
|
|
/** @noinspection PhpUnused */
|
|
|
|
class LoginController extends Controller
|
|
{
|
|
|
|
public function behaviors()
|
|
{
|
|
$behaviors = parent::behaviors();
|
|
|
|
$behaviors['corsFilter'] = [
|
|
'class' => \yii\filters\Cors::className(),
|
|
'cors' => [
|
|
// restrict access to
|
|
'Origin' => ['https://botondfitness.hu'],
|
|
// Allow credentials (cookies, authorization headers, etc.) to be exposed to the browser
|
|
'Access-Control-Allow-Credentials' => true,
|
|
]
|
|
];
|
|
return $behaviors;
|
|
}
|
|
|
|
/**
|
|
* hash for password test is:
|
|
* $2y$13$D2BauYE2nhCdVDNatT9BMeWGxOvi5t5V6W2OUjr6sj2FRpb317Cpq
|
|
*
|
|
*/
|
|
/** @noinspection PhpUnused */
|
|
public function actionLogin()
|
|
{
|
|
$form = new LoginForm();
|
|
|
|
$form->load(\Yii::$app->request->post(), '');
|
|
|
|
if ($form->validate()) {
|
|
|
|
/** @var Jwt $jwt */
|
|
$jwt = Yii::$app->jwt;
|
|
$signer = $jwt->getSigner('HS256');
|
|
$key = $jwt->getKey();
|
|
$time = time();
|
|
|
|
// Adoption for lcobucci/jwt ^4.0 version
|
|
$token = $jwt->getBuilder()
|
|
->issuedBy('customerapi')// Configures the issuer (iss claim)
|
|
->permittedFor('customer')// Configures the audience (aud claim)
|
|
->identifiedBy('A989C57D19E2AF756BA9585AC4CFAF7974AE3D2BCA7CCA7307B39AB28CC7C2C8', true)// Configures the id (jti claim), replicating as a header item
|
|
->issuedAt($time)// Configures the time that the token was issue (iat claim)
|
|
->expiresAt($time + 3600)// Configures the expiration time of the token (exp claim)
|
|
->withClaim('uid', $form->getCustomer()->getId())// Configures a new claim, called "uid"
|
|
->getToken($signer, $key); // Retrieves the generated token
|
|
|
|
return $this->asJson([
|
|
'token' => (string)$token,
|
|
]);
|
|
} else {
|
|
throw new UnauthorizedHttpException("Hibás e-mail cím vagy jelszó!");
|
|
}
|
|
}
|
|
|
|
}
|