Code Coverage |
||||||||||
Lines |
Functions and Methods |
Classes and Traits |
||||||||
| Total | |
100.00% |
6 / 6 |
|
100.00% |
2 / 2 |
CRAP | |
100.00% |
1 / 1 |
| ChainKeyResolver | |
100.00% |
6 / 6 |
|
100.00% |
2 / 2 |
4 | |
100.00% |
1 / 1 |
| __construct | |
100.00% |
1 / 1 |
|
100.00% |
1 / 1 |
1 | |||
| publicKeys | |
100.00% |
5 / 5 |
|
100.00% |
1 / 1 |
3 | |||
| 1 | <?php |
| 2 | |
| 3 | declare(strict_types=1); |
| 4 | |
| 5 | namespace LambdaTwelve\OneRecord\Auth\Jwt; |
| 6 | |
| 7 | /** |
| 8 | * Several resolvers as one: pinned PEM keys for some issuers, JWKS documents |
| 9 | * for others, the host's own signing key for its own token endpoint. The |
| 10 | * first resolver that knows the issuer answers; the rest are not consulted, |
| 11 | * so an issuer is trusted by exactly one source. |
| 12 | */ |
| 13 | final class ChainKeyResolver implements KeyResolver |
| 14 | { |
| 15 | /** @var list<KeyResolver> */ |
| 16 | private readonly array $resolvers; |
| 17 | |
| 18 | public function __construct(KeyResolver ...$resolvers) |
| 19 | { |
| 20 | $this->resolvers = array_values($resolvers); |
| 21 | } |
| 22 | |
| 23 | public function publicKeys(string $issuer, ?string $keyId): array |
| 24 | { |
| 25 | foreach ($this->resolvers as $resolver) { |
| 26 | $keys = $resolver->publicKeys($issuer, $keyId); |
| 27 | if ($keys !== []) { |
| 28 | return $keys; |
| 29 | } |
| 30 | } |
| 31 | |
| 32 | return []; |
| 33 | } |
| 34 | } |