src/Security/LoginFormAuthenticator.php line 18

Open in your IDE?
  1. <?php
  2. namespace App\Security;
  3. use Symfony\Component\HttpFoundation\Request;
  4. use Symfony\Component\HttpFoundation\RedirectResponse;
  5. use Symfony\Component\HttpFoundation\Response;
  6. use Symfony\Component\Routing\Generator\UrlGeneratorInterface;
  7. use Symfony\Component\Security\Core\Exception\CustomUserMessageAuthenticationException;
  8. use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
  9. use Symfony\Component\Security\Http\Authenticator\AbstractLoginFormAuthenticator;
  10. use Symfony\Component\Security\Http\Authenticator\Passport\Passport;
  11. use Symfony\Component\Security\Http\Authenticator\Passport\Badge\UserBadge;
  12. use Symfony\Component\Security\Http\Authenticator\Passport\Badge\CsrfTokenBadge;
  13. use Symfony\Component\Security\Http\Authenticator\Passport\Credentials\PasswordCredentials;
  14. use Symfony\Component\Security\Http\Util\TargetPathTrait;
  15. class LoginFormAuthenticator extends AbstractLoginFormAuthenticator
  16. {
  17.     use TargetPathTrait;
  18.     public const LOGIN_ROUTE 'new_login';
  19.     /** @var UrlGeneratorInterface */
  20.     private $urlGenerator;
  21.     public function __construct(UrlGeneratorInterface $urlGenerator)
  22.     {
  23.         $this->urlGenerator $urlGenerator;
  24.     }
  25.     public function authenticate(Request $request): Passport
  26.     {
  27.         $username       = (string) $request->request->get('_username''');
  28.         $password       = (string) $request->request->get('_password''');
  29.         $csrfToken      = (string) $request->request->get('_csrf_token''');
  30.         $inputCaptcha   = (string) $request->request->get('captcha''');
  31.         $session        $request->getSession();
  32.         $sessionCaptcha = (string) $session->get('captcha''');
  33.         // === Validasi captcha ===
  34.         if (!$sessionCaptcha || strcasecmp($inputCaptcha$sessionCaptcha) !== 0) {
  35.             $session->remove('captcha');
  36.             throw new CustomUserMessageAuthenticationException('Captcha salah. Silakan coba lagi.');
  37.         }
  38.         $session->remove('captcha');
  39.         return new Passport(
  40.             new UserBadge($username),
  41.             new PasswordCredentials($password),
  42.             [
  43.                 new CsrfTokenBadge('my_csrf_token'$csrfToken),
  44.             ]
  45.         );
  46.     }
  47.     public function onAuthenticationSuccess(Request $requestTokenInterface $tokenstring $firewallName): ?Response
  48.     {
  49.         // Jika user awalnya akses halaman proteksi, balikan ke sana
  50.         if ($targetPath $this->getTargetPath($request->getSession(), $firewallName)) {
  51.             return new RedirectResponse($targetPath);
  52.         }
  53.         // Atau redirect default sesudah login
  54.         return new RedirectResponse($this->urlGenerator->generate('dashboard'));
  55.     }
  56.     protected function getLoginUrl(Request $request): string
  57.     {
  58.         return $this->urlGenerator->generate(self::LOGIN_ROUTE);
  59.     }
  60. }