PluginProbe
Media Cloud Sync / 1.4.2
Media Cloud Sync v1.4.2
1.4.2 1.4.1 1.4.0 1.3.12 1.3.11 1.3.10 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.2.0 1.2.10 1.2.11 1.2.12 1.2.13 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 All 36 releases
← All changes | includes/sdk/s3/Aws/Auth/AuthSelectionMiddleware.php +43 -9 1.2.13 → 1.4.2 View file →
@@ -2,8 +2,9 @@
2 2
3 3 namespace Dudlewebs\WPMCS\s3\Aws\Auth;
4 4
5 5 use Dudlewebs\WPMCS\s3\Aws\Api\Service;
6 +use Dudlewebs\WPMCS\s3\Aws\Auth\Exception\UnresolvedAuthSchemeException;
6 7 use Dudlewebs\WPMCS\s3\Aws\CommandInterface;
7 8 use Closure;
8 9 use Dudlewebs\WPMCS\s3\GuzzleHttp\Promise\Promise;
9 10 /**
@@ -23,32 +24,37 @@
23 24 /** @var AuthSchemeResolverInterface */
24 25 private $authResolver;
25 26 /** @var Service */
26 27 private $api;
28 + /** @var array|null */
29 + private ?array $configuredAuthSchemes;
27 30 /**
28 31 * Create a middleware wrapper function
29 32 *
30 33 * @param AuthSchemeResolverInterface $authResolver
31 34 * @param Service $api
35 + * @param array|null $configuredAuthSchemes
36 + *
32 37 * @return Closure
33 38 */
34 - public static function wrap(AuthSchemeResolverInterface $authResolver, Service $api) : Closure
39 + public static function wrap(AuthSchemeResolverInterface $authResolver, Service $api, ?array $configuredAuthSchemes) : Closure
35 40 {
36 - return function (callable $handler) use($authResolver, $api) {
37 - return new self($handler, $authResolver, $api);
41 + return function (callable $handler) use($authResolver, $api, $configuredAuthSchemes) {
42 + return new self($handler, $authResolver, $api, $configuredAuthSchemes);
38 43 };
39 44 }
40 45 /**
41 46 * @param callable $nextHandler
42 - * @param $authResolver
43 - * @param callable $identityProvider
47 + * @param AuthSchemeResolverInterface $authResolver
44 48 * @param Service $api
49 + * @param array|null $configuredAuthSchemes
45 50 */
46 - public function __construct(callable $nextHandler, AuthSchemeResolverInterface $authResolver, Service $api)
51 + public function __construct(callable $nextHandler, AuthSchemeResolverInterface $authResolver, Service $api, ?array $configuredAuthSchemes = null)
47 52 {
48 53 $this->nextHandler = $nextHandler;
49 54 $this->authResolver = $authResolver;
50 55 $this->api = $api;
56 + $this->configuredAuthSchemes = $configuredAuthSchemes;
51 57 }
52 58 /**
53 59 * @param CommandInterface $command
54 60 *
@@ -67,12 +73,40 @@
67 73 $resolver = $command['@context']['auth_scheme_resolver'];
68 74 } else {
69 75 $resolver = $this->authResolver;
70 76 }
71 - $selectedAuthScheme = $resolver->selectAuthScheme($resolvableAuth, ['unsigned_payload' => $unsignedPayload]);
72 - if (!empty($selectedAuthScheme)) {
73 - $command['@context']['signature_version'] = $selectedAuthScheme;
77 + try {
78 + $authSchemeList = $this->buildAuthSchemeList($resolvableAuth, $command['@context']['auth_scheme_preference'] ?? null);
79 + $selectedAuthScheme = $resolver->selectAuthScheme($authSchemeList, ['unsigned_payload' => $unsignedPayload]);
80 + if (!empty($selectedAuthScheme)) {
81 + $command['@context']['signature_version'] = $selectedAuthScheme;
82 + }
83 + } catch (UnresolvedAuthSchemeException $ignored) {
84 + // There was an error resolving auth
85 + // The signature version will fall back to the modeled `signatureVersion`
86 + // or auth schemes resolved during endpoint resolution
74 87 }
75 88 }
76 89 return $nextHandler($command);
90 + }
91 + /**
92 + * Prioritizes auth schemes according to user preference order.
93 + * User-preferred schemes that are available will be placed first,
94 + * followed by remaining available schemes.
95 + *
96 + * @param array $resolvableAuthSchemeList Available auth schemes
97 + * @param array|null $commandConfiguredAuthSchemes Command-level preferences (overrides config)
98 + *
99 + * @return array Reordered auth schemes with user preferences first
100 + */
101 + private function buildAuthSchemeList(array $resolvableAuthSchemeList, ?array $commandConfiguredAuthSchemes) : array
102 + {
103 + $userConfiguredAuthSchemes = $commandConfiguredAuthSchemes ?? $this->configuredAuthSchemes;
104 + if (empty($userConfiguredAuthSchemes)) {
105 + return $resolvableAuthSchemeList;
106 + }
107 + $prioritizedAuthSchemes = \array_intersect($userConfiguredAuthSchemes, $resolvableAuthSchemeList);
108 + // Get remaining schemes not in user preferences
109 + $remainingAuthSchemes = \array_diff($resolvableAuthSchemeList, $prioritizedAuthSchemes);
110 + return \array_merge($prioritizedAuthSchemes, $remainingAuthSchemes);
77 111 }
78 112 }