/
HttpsEnforcerMiddleware.php
98 lines (90 loc) · 3.19 KB
/
HttpsEnforcerMiddleware.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
<?php
declare(strict_types=1);
/**
* CakePHP(tm) : Rapid Development Framework (http://cakephp.org)
* Copyright (c) Cake Software Foundation, Inc. (http://cakefoundation.org)
*
* Licensed under The MIT License
* For full copyright and license information, please see the LICENSE.txt
* Redistributions of files must retain the above copyright notice.
*
* @copyright Copyright (c) Cake Software Foundation, Inc. (http://cakefoundation.org)
* @link http://cakephp.org CakePHP(tm) Project
* @since 4.0.0
* @license http://www.opensource.org/licenses/mit-license.php MIT License
*/
namespace Cake\Http\Middleware;
use Cake\Core\Configure;
use Cake\Http\Exception\BadRequestException;
use Laminas\Diactoros\Response\RedirectResponse;
use Psr\Http\Message\ResponseInterface;
use Psr\Http\Message\ServerRequestInterface;
use Psr\Http\Server\MiddlewareInterface;
use Psr\Http\Server\RequestHandlerInterface;
/**
* Enforces use of HTTPS (SSL) for requests.
*/
class HttpsEnforcerMiddleware implements MiddlewareInterface
{
/**
* Configuration.
*
* ### Options
*
* - `redirect` - If set to true (default) redirects GET requests to same URL with https.
* - `statusCode` - Status code to use in case of redirect, defaults to 301 - Permanent redirect.
* - `headers` - Array of response headers in case of redirect.
* - `disableOnDebug` - Whether HTTPS check should be disabled when debug is on. Default `true`.
*
* @var array
* @psalm-var array{redirect: bool, statusCode: int, headers: array, disableOnDebug: bool}
*/
protected $config = [
'redirect' => true,
'statusCode' => 301,
'headers' => [],
'disableOnDebug' => true,
];
/**
* Constructor
*
* @param array $config The options to use.
* @see self::$config
*/
public function __construct(array $config = [])
{
$this->config = $config + $this->config;
}
/**
* Check whether request has been made using HTTPS.
*
* Depending on the configuration and request method, either redirects to
* same URL with https or throws an exception.
*
* @param \Psr\Http\Message\ServerRequestInterface $request The request.
* @param \Psr\Http\Server\RequestHandlerInterface $handler The request handler.
* @return \Psr\Http\Message\ResponseInterface A response.
* @throws \Cake\Http\Exception\BadRequestException
*/
public function process(ServerRequestInterface $request, RequestHandlerInterface $handler): ResponseInterface
{
if (
$request->getUri()->getScheme() === 'https'
|| ($this->config['disableOnDebug']
&& Configure::read('debug'))
) {
return $handler->handle($request);
}
if ($this->config['redirect'] && $request->getMethod() === 'GET') {
$uri = $request->getUri()->withScheme('https');
return new RedirectResponse(
$uri,
$this->config['statusCode'],
$this->config['headers']
);
}
throw new BadRequestException(
'Requests to this URL must be made with HTTPS.'
);
}
}