feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: User activation checks and utility functions. - #580

Merged
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check
Feb 5, 2023
Merged

feat: User activation checks and utility functions.#580
kenjis merged 5 commits into
codeigniter4:developfrom
lonnieezell:active-check

Conversation

@lonnieezell

@lonnieezelllonnieezell commented Jan 4, 2023

Copy link
Copy Markdown
Member

Fixes#459

Previously, the active column for the user was not being used except that the EmailActivator flow would set it. This PR addresses this by:

  • Adding a new Activatable trait that is used on the User entity. This provides methods to check if a user is activated or not, and utility methods to activate/deactivate that user.
  • The SessionAuth and TokenAuth filters are updated to check the user's active status and redirect to login/return a 403 status code, respectively, when they aren't active. This takes into account if no activator is required after registration.

Comment threaddocs/authorization.md Outdated
Comment threadsrc/Filters/SessionAuth.php
Comment threadsrc/Filters/TokenAuth.php
Comment threadsrc/Language/en/Auth.php Outdated
Comment threadsrc/Language/fa/Auth.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php Outdated
Comment threadsrc/Traits/Activatable.php
@kenjiskenjis changed the title feat: User activation checks and utility functions. Fixes #459feat: User activation checks and utility functions.Jan 4, 2023
@kenjiskenjis added the enhancement New feature or request label Jan 4, 2023
Comment threadsrc/Language/ja/Auth.php Outdated
@kenjiskenjis added the breaking change Pull requests that may break existing functionalities label Jan 5, 2023
return redirect()->to('/login');
return service('response')
->setStatusCode(Response::HTTP_FORBIDDEN)
->setJson(['message' => lang('Auth.badToken')]);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a breaking change. It is better to document it.

#433 suggests 401, not 403. Which is better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for 401. For example, I already using it in few deployments with own api-filter. I would like to switch to this one if it's will be suitable for me.

@jozefrebjakjozefrebjakJan 5, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

401 Unauthorized is the status code to return when the client provides no credentials or invalid credentials. 403 Forbidden is the status code to return when a client has valid credentials but not enough privileges to perform an action on a resource.

Receiving a 403 response is the server telling you, “I’m sorry. I know who you are–I believe who you say you are–but you just don’t have permission to access this resource. Maybe if you ask the system administrator nicely, you’ll get permission. But please don’t bother me again until your predicament changes.”

In summary, a 401 Unauthorized response should be used for missing or bad authentication, and a 403 Forbidden response should be used afterwards, when the user is authenticated but isn’t authorized to perform the requested operation on the given resource.

@lonnieezell Here we are mixing authentication and authorization. Maybe we need to first check if a client provided a valid token and if not, return 401 and after that, check, scopes and if there is no valid scope, return 403.

@kenjiskenjisJan 5, 2023

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HyperText Transfer Protocol (HTTP) 401 Unauthorized response status code indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource.

This status code is similar to the 403 Forbidden status code, except that in situations resulting in this status code, user authentication can allow access to the resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401

The HTTP 403 Forbidden response status code indicates that the server understands the request but refuses to authorize it.

This status is similar to 401, but for the 403 Forbidden status code, re-authenticating makes no difference. The access is tied to the application logic, such as insufficient rights to a resource.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These make sense. First check will result in a 401, with the not-activated check being a 403.

@datamwebdatamweb reopened this Jan 12, 2023
/**
* Activates the user.
*/
public function activate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the return type to void?
The UserModel::update() throws an exception when the update fails.
So returning bool does not make sense.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless it's changing in a PR, update() currently returns a boolean. Changing this to void throws errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I sent a PR #626

/**
* Deactivates the user.
*/
public function deactivate(): bool

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same above.

@datamweb

Copy link
Copy Markdown
Collaborator

We have a new language file pt-BR, please add:

'activationBlocked' => '(to be translated) You must activate your account before logging in.',

Also conflict in file src/Entities/User.php.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, we can address your opinion separately in PR. This PR has taken too long.

@kenjis
kenjis merged commit 112df4a into codeigniter4:developFeb 5, 2023
@lonnieezell
lonnieezell deleted the active-check branch February 5, 2023 04:52
@lonnieezell

Copy link
Copy Markdown
MemberAuthor

Thanks!

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking changePull requests that may break existing functionalitiesenhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: when active field in users table is false users can login

4 participants

@lonnieezell@datamweb@kenjis@jozefrebjak