feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: HMAC SHA256 Authentication - #795

Merged
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC
Sep 19, 2023
Merged

feat: HMAC SHA256 Authentication#795
kenjis merged 41 commits into
codeigniter4:developfrom
geniza-ai:feature/HMAC

Conversation

@tswagger

@tswaggertswagger commented Aug 23, 2023

Copy link
Copy Markdown
Contributor

Adding HMAC-SHA256 as an authenticator. This method has a slight security advantage to a standard token authentication by signing the request with a shared secret.

Usage and coding mirrors closely the established Access Token Authentication classes and methods.

References:

@tswaggertswagger changed the title HMAC SHA256feat: HMAC SHA256 AuthenticationAug 23, 2023
@kenjiskenjis added GPG-Signing needed Pull requests that need GPG-Signing enhancement New feature or request labels Aug 24, 2023
@kenjis

Copy link
Copy Markdown
Member

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis

Copy link
Copy Markdown
Member

And we don't use git merge to update PR branches.
Please use git rebase instead.
See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#updating-your-branch

@tswagger

Copy link
Copy Markdown
ContributorAuthor

Thank you for sending this PR!

You must GPG-sign your work, certifying that you either wrote the work or otherwise have the right to pass it on to an open-source project. See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md#signing

@kenjis My apologies, I thought I had that setup correctly. Since I obviously didn't, how do I retroactively sign what I have submitted?

@kenjis

Copy link
Copy Markdown
Member

See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/workflow.md#gpg-signing-old-commits

@tswagger

Copy link
Copy Markdown
ContributorAuthor

@kenjis I have rebased and signed my code. I appreciate your assistance on that.

@kenjiskenjis removed the GPG-Signing needed Pull requests that need GPG-Signing label Aug 25, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@tswagger

tswagger commented Aug 25, 2023

Copy link
Copy Markdown
ContributorAuthor

I am not sure how you would like me to address the final failed check. I intentionally mirrored the Authorize Tokens classes. I could create a shared trait or abstract parent class, but some of the differences, while subtle, are major enough to make that challenging.

@kenjis

kenjis commented Aug 25, 2023

Copy link
Copy Markdown
Member

We will give it some consideration, so please leave it as it is.
In any case, this PR is too large to review easily.

Adding Trait or abstract classes could make the design worse.
We can also suppress errors by PHPCPD.

@tswagger

Copy link
Copy Markdown
ContributorAuthor

That was my thought. I will leave it in your hands. Please let me know if you need anything else from me.

Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threadsrc/Authentication/Authenticators/HMAC_SHA256.php Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
@datamwebdatamweb closed this Sep 5, 2023
@datamwebdatamweb reopened this Sep 5, 2023
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md Outdated
Comment threaddocs/authentication.md
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/guides/api_hmac_keys.md Outdated
Comment threaddocs/authentication.md
tswaggerand others added 22 commits September 18, 2023 09:07
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Co-authored-by: John Paul E. Balandan, CPA <paulbalandan@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Added AuthToken config as a separate config for Token/HMAC auth from JWT
Updated test to reflect logging adjustment change.
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: kenjis <kenji.uui@gmail.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Co-authored-by: Pooya Parsa <pooya_parsa_dadashi@yahoo.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
Signed-off-by: tswagger <tim@renowne.com>
@kenjis

Copy link
Copy Markdown
Member

Cannot reproduce the PHPStan errors.

(feature/HMAC $)$ vendor/bin/phpstan
Note: Using configuration file /Users/kenji/work/codeigniter/official/codeigniter-shield/phpstan.neon.dist.
176/176 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
[OK] No errors 
 ------ -------------------------------------------------------------------- Line src/Models/UserModel.php ------ -------------------------------------------------------------------- 215 Offset 'email' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 216 Cannot unset offset 'email' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 217 Offset 'password_hash' does not exist on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. 218 Cannot unset offset 'password_hash' on array{username: string, status: string, status_message: string, active: bool, last_active: string, deleted_at: string}. ------ -------------------------------------------------------------------- ------ ------------------------------------------------------------------- Line tests/Unit/UserTest.php ------ ------------------------------------------------------------------- Ignored error pattern #^Cannot access property \$active on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. Ignored error pattern #^Cannot access property \$password_hash on array\|object\.$# in path /home/runner/work/shield/shield/tests/Unit/UserTest.php was not matched in reported errors. ------ ------------------------------------------------------------------- Error: [ERROR] Found 6 errors 

https://github.com/codeigniter4/shield/actions/runs/6223741069/job/16907463318?pr=795

@kenjiskenjis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kenjis
kenjis merged commit a3030f9 into codeigniter4:developSep 19, 2023
@kenjis

Copy link
Copy Markdown
Member

@tswagger Thank you!

@kenjis

kenjis commented Sep 19, 2023

Copy link
Copy Markdown
Member

Oh, my dependencies were old.

 - Upgrading codeigniter/coding-standard (v1.7.8 => v1.7.9)
- Upgrading codeigniter/phpstan-codeigniter (v1.2.0.70400 => v1.3.0.70400)
- Upgrading nexusphp/cs-config (v3.15.0 => v3.16.0)
- Upgrading phpstan/phpdoc-parser (1.24.0 => 1.24.1)

Fixed by #840

@kenjiskenjis mentioned this pull request Sep 19, 2023
5 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tswagger@kenjis@datamweb@paulbalandan