Code Coverage |
||||||||||
Lines |
Functions and Methods |
Classes and Traits |
||||||||
| Total | |
100.00% |
6 / 6 |
|
100.00% |
2 / 2 |
CRAP | |
100.00% |
1 / 1 |
| StaticKeyResolver | |
100.00% |
6 / 6 |
|
100.00% |
2 / 2 |
6 | |
100.00% |
1 / 1 |
| __construct | |
100.00% |
2 / 2 |
|
100.00% |
1 / 1 |
3 | |||
| publicKeys | |
100.00% |
4 / 4 |
|
100.00% |
1 / 1 |
3 | |||
| 1 | <?php |
| 2 | |
| 3 | declare(strict_types=1); |
| 4 | |
| 5 | namespace LambdaTwelve\OneRecord\Auth\Jwt; |
| 6 | |
| 7 | /** |
| 8 | * Trusted issuers configured in code: each with one PEM public key, a list |
| 9 | * of them, or a map of key id to PEM. This is what a host with a handful of |
| 10 | * partners needs; JwksKeyResolver covers identity providers that publish keys. |
| 11 | */ |
| 12 | final class StaticKeyResolver implements KeyResolver |
| 13 | { |
| 14 | /** @var array<string, array<string|int, string>> */ |
| 15 | private array $keys = []; |
| 16 | |
| 17 | /** |
| 18 | * @param array<string, string|list<string>|array<string, string>> $issuers issuer => PEM, PEMs, or kid => PEM |
| 19 | */ |
| 20 | public function __construct(array $issuers) |
| 21 | { |
| 22 | foreach ($issuers as $issuer => $keys) { |
| 23 | $this->keys[$issuer] = \is_string($keys) ? [$keys] : $keys; |
| 24 | } |
| 25 | } |
| 26 | |
| 27 | public function publicKeys(string $issuer, ?string $keyId): array |
| 28 | { |
| 29 | $keys = $this->keys[$issuer] ?? []; |
| 30 | if ($keyId !== null && isset($keys[$keyId])) { |
| 31 | return [$keys[$keyId]]; |
| 32 | } |
| 33 | |
| 34 | return array_values($keys); |
| 35 | } |
| 36 | } |