AdminTokenService.php 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138
  1. <?php
  2. /**
  3. * Copyright © Magento, Inc. All rights reserved.
  4. * See COPYING.txt for license details.
  5. */
  6. namespace Magento\Integration\Model;
  7. use Magento\Framework\Exception\AuthenticationException;
  8. use Magento\Framework\Exception\LocalizedException;
  9. use Magento\Integration\Model\CredentialsValidator;
  10. use Magento\Integration\Model\Oauth\Token as Token;
  11. use Magento\Integration\Model\Oauth\TokenFactory as TokenModelFactory;
  12. use Magento\Integration\Model\ResourceModel\Oauth\Token\CollectionFactory as TokenCollectionFactory;
  13. use Magento\User\Model\User as UserModel;
  14. use Magento\Integration\Model\Oauth\Token\RequestThrottler;
  15. /**
  16. * Class to handle token generation for Admins
  17. */
  18. class AdminTokenService implements \Magento\Integration\Api\AdminTokenServiceInterface
  19. {
  20. /**
  21. * Token Model
  22. *
  23. * @var TokenModelFactory
  24. */
  25. private $tokenModelFactory;
  26. /**
  27. * User Model
  28. *
  29. * @var UserModel
  30. */
  31. private $userModel;
  32. /**
  33. * @var \Magento\Integration\Model\CredentialsValidator
  34. */
  35. private $validatorHelper;
  36. /**
  37. * Token Collection Factory
  38. *
  39. * @var TokenCollectionFactory
  40. */
  41. private $tokenModelCollectionFactory;
  42. /**
  43. * @var RequestThrottler
  44. */
  45. private $requestThrottler;
  46. /**
  47. * Initialize service
  48. *
  49. * @param TokenModelFactory $tokenModelFactory
  50. * @param UserModel $userModel
  51. * @param TokenCollectionFactory $tokenModelCollectionFactory
  52. * @param \Magento\Integration\Model\CredentialsValidator $validatorHelper
  53. */
  54. public function __construct(
  55. TokenModelFactory $tokenModelFactory,
  56. UserModel $userModel,
  57. TokenCollectionFactory $tokenModelCollectionFactory,
  58. CredentialsValidator $validatorHelper
  59. ) {
  60. $this->tokenModelFactory = $tokenModelFactory;
  61. $this->userModel = $userModel;
  62. $this->tokenModelCollectionFactory = $tokenModelCollectionFactory;
  63. $this->validatorHelper = $validatorHelper;
  64. }
  65. /**
  66. * {@inheritdoc}
  67. */
  68. public function createAdminAccessToken($username, $password)
  69. {
  70. $this->validatorHelper->validate($username, $password);
  71. $this->getRequestThrottler()->throttle($username, RequestThrottler::USER_TYPE_ADMIN);
  72. $this->userModel->login($username, $password);
  73. if (!$this->userModel->getId()) {
  74. $this->getRequestThrottler()->logAuthenticationFailure($username, RequestThrottler::USER_TYPE_ADMIN);
  75. /*
  76. * This message is same as one thrown in \Magento\Backend\Model\Auth to keep the behavior consistent.
  77. * Constant cannot be created in Auth Model since it uses legacy translation that doesn't support it.
  78. * Need to make sure that this is refactored once exception handling is updated in Auth Model.
  79. */
  80. throw new AuthenticationException(
  81. __(
  82. 'The account sign-in was incorrect or your account is disabled temporarily. '
  83. . 'Please wait and try again later.'
  84. )
  85. );
  86. }
  87. $this->getRequestThrottler()->resetAuthenticationFailuresCount($username, RequestThrottler::USER_TYPE_ADMIN);
  88. return $this->tokenModelFactory->create()->createAdminToken($this->userModel->getId())->getToken();
  89. }
  90. /**
  91. * Revoke token by admin id.
  92. *
  93. * The function will delete the token from the oauth_token table.
  94. *
  95. * @param int $adminId
  96. * @return bool
  97. * @throws \Magento\Framework\Exception\LocalizedException
  98. */
  99. public function revokeAdminAccessToken($adminId)
  100. {
  101. $tokenCollection = $this->tokenModelCollectionFactory->create()->addFilterByAdminId($adminId);
  102. if ($tokenCollection->getSize() == 0) {
  103. throw new LocalizedException(__('This user has no tokens.'));
  104. }
  105. try {
  106. foreach ($tokenCollection as $token) {
  107. $token->delete();
  108. }
  109. } catch (\Exception $e) {
  110. throw new LocalizedException(__("The tokens couldn't be revoked."));
  111. }
  112. return true;
  113. }
  114. /**
  115. * Get request throttler instance
  116. *
  117. * @return RequestThrottler
  118. * @deprecated 100.0.4
  119. */
  120. private function getRequestThrottler()
  121. {
  122. if (!$this->requestThrottler instanceof RequestThrottler) {
  123. return \Magento\Framework\App\ObjectManager::getInstance()->get(RequestThrottler::class);
  124. }
  125. return $this->requestThrottler;
  126. }
  127. }