Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
100.00% covered (success)
100.00%
8 / 8
100.00% covered (success)
100.00%
1 / 1
CRAP
100.00% covered (success)
100.00%
1 / 1
AccessDelegationsEndpoint
100.00% covered (success)
100.00%
8 / 8
100.00% covered (success)
100.00%
1 / 1
5
100.00% covered (success)
100.00%
1 / 1
 handle
100.00% covered (success)
100.00%
8 / 8
100.00% covered (success)
100.00%
1 / 1
5
1<?php
2
3declare(strict_types=1);
4
5namespace LambdaTwelve\OneRecord\Server\Endpoint;
6
7use LambdaTwelve\OneRecord\Api\AccessDelegation;
8use LambdaTwelve\OneRecord\Server\ActionRequests;
9use LambdaTwelve\OneRecord\Server\Http\ContentNegotiation;
10use LambdaTwelve\OneRecord\Server\Http\HttpException;
11use LambdaTwelve\OneRecord\Server\Http\Negotiated;
12use LambdaTwelve\OneRecord\Server\Spi\Action;
13use LambdaTwelve\OneRecord\Server\Spi\Agent;
14use LambdaTwelve\OneRecord\Server\Spi\Decision;
15use LambdaTwelve\OneRecord\Vocabulary\Generated\Api;
16use Psr\Http\Message\ResponseInterface;
17use Psr\Http\Message\ServerRequestInterface;
18
19/**
20 * POST /access-delegations: a request for permissions on this server's
21 * objects, for the requester or a third party, becomes a pending
22 * AccessDelegationRequest (201). The 2.2 or 2.3 shape is read according to
23 * the body's declared version.
24 */
25final class AccessDelegationsEndpoint extends AbstractEndpoint
26{
27    public function handle(ServerRequestInterface $request, Agent $agent, Negotiated $negotiated, array $parameters): ResponseInterface
28    {
29        $bodyVersion = (new ContentNegotiation($this->services->config))->bodyVersion($request, $negotiated);
30        $delegation = AccessDelegation::fromJsonLd($this->services->body->json($request), $bodyVersion);
31        foreach ($delegation->logisticsObjects as $object) {
32            $hidden = $this->services->policy->decide($agent, Action::ReadLogisticsObject, $object) === Decision::Hide;
33            if (!$this->services->config->isLocal($object) || $hidden || !$this->services->objects->exists($object)) {
34                throw HttpException::badRequest(\sprintf('"%s" is not a logistics object of this server.', $object->value), Api::hasLogisticsObject, 'Invalid resource');
35            }
36        }
37        $created = (new ActionRequests($this->services))->create($delegation, $agent->iri);
38
39        return $this->services->responder->empty(201, $negotiated, ['Location' => $created->iri->value, 'Type' => Api::AccessDelegationRequest]);
40    }
41}