feat: proper logging to dedicated audit channel
This commit is contained in:
@@ -49,6 +49,9 @@ class MyEpAuthenticator extends AbstractAuthenticator
|
||||
try {
|
||||
$accessToken = $this->client->fetchAccessToken($request);
|
||||
} catch (AuthorizationRequestException|IdentityProviderException $e) {
|
||||
$this->logger->error('Login via MyE&P failed due to unobtainable access token', [
|
||||
'exception' => $e,
|
||||
]);
|
||||
throw new CustomUserMessageAuthenticationException('Invalid token');
|
||||
}
|
||||
|
||||
@@ -110,11 +113,21 @@ class MyEpAuthenticator extends AbstractAuthenticator
|
||||
{
|
||||
// User is expected to have at least one role
|
||||
if (false === isset($userinfo['roles']) || 0 === count($userinfo['roles'])) {
|
||||
// Claim keys only, the payload itself carries the full profile
|
||||
$this->logger->warning('Login via MyE&P failed due to missing roles claim', [
|
||||
'claims' => array_keys($userinfo),
|
||||
]);
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
// User is expected to have at least one of the roles teamer, manager, house manager or admin
|
||||
if ([] === array_intersect(self::ELIGIBLE_ROLES, $userinfo['roles'])) {
|
||||
$this->logger->warning('Login via MyE&P failed due to lack of an eligible role', [
|
||||
'roles' => $userinfo['roles'],
|
||||
'eligible_roles' => self::ELIGIBLE_ROLES,
|
||||
]);
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@ use League\OAuth2\Client\Provider\AbstractProvider;
|
||||
use League\OAuth2\Client\Provider\Exception\IdentityProviderException;
|
||||
use League\OAuth2\Client\Provider\GenericProvider;
|
||||
use League\OAuth2\Client\Token\AccessTokenInterface;
|
||||
use Psr\Log\LoggerInterface;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\OptionsResolver\OptionsResolver;
|
||||
use Symfony\Component\Routing\Generator\UrlGeneratorInterface;
|
||||
@@ -14,8 +15,11 @@ class MyEpClient
|
||||
{
|
||||
private array $config;
|
||||
|
||||
public function __construct(private readonly UrlGeneratorInterface $urlGenerator, array $options)
|
||||
{
|
||||
public function __construct(
|
||||
private readonly UrlGeneratorInterface $urlGenerator,
|
||||
private readonly LoggerInterface $logger,
|
||||
array $options,
|
||||
) {
|
||||
$this->config = $this->resolveConfig($options);
|
||||
}
|
||||
|
||||
@@ -26,6 +30,7 @@ class MyEpClient
|
||||
public function fetchAccessToken(Request $request): AccessTokenInterface
|
||||
{
|
||||
if (null === $code = $request->query->get('code')) {
|
||||
$this->logger->error('OAuth2 login request missing code');
|
||||
throw new AuthorizationRequestException('Missing code', 400, $request);
|
||||
}
|
||||
|
||||
@@ -36,6 +41,7 @@ class MyEpClient
|
||||
|| $request->query->get('state') !== $session->get('oauth2state')
|
||||
) {
|
||||
$session->remove('oauth2state');
|
||||
$this->logger->error('OAuth2 login request missing state or mismatch');
|
||||
throw new AuthorizationRequestException('Missing state or mismatch', 400, $request);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user