<?php
namespace App\Security;
use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\HttpFoundation\RedirectResponse;
use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Http\Authenticator\AbstractLoginFormAuthenticator;
use Symfony\Component\Security\Http\Authenticator\Passport\Badge\UserBadge;
use Symfony\Component\Security\Http\Authenticator\Passport\Badge\CsrfTokenBadge;
use Symfony\Component\Security\Http\Authenticator\Passport\Passport;
use Symfony\Component\Security\Core\Exception\CustomUserMessageAuthenticationException;
use Symfony\Component\Security\Core\Exception\AuthenticationException;
use Symfony\Component\Security\Http\Authenticator\Passport\Credentials\PasswordCredentials;
use Symfony\Component\Routing\RouterInterface;
use Doctrine\ORM\EntityManagerInterface;
use App\Entity\Admin;
class AdminLoginFormAuthenticator extends AbstractLoginFormAuthenticator
{
public function __construct(
protected EntityManagerInterface $entityManager,
protected RouterInterface $router,
) {}
/**
* Called on every request to decide if this authenticator should be
* used for the request. Returning `false` will cause this authenticator
* to be skipped.
*/
public function supports(Request $request): bool
{
return 'admin.login' === $request->attributes->get('_route') && $request->isMethod('POST');
}
/**
* Return the URL to the login page.
*/
protected function getLoginUrl(Request $request): string
{
return $this->router->generate('admin.login');
}
public function authenticate(Request $request): Passport
{
$password = $request->request->get('password');
$username = $request->request->get('username');
$csrfToken = $request->request->get('csrf_token');
return new Passport(
new UserBadge($username),
new PasswordCredentials($password),
[new CsrfTokenBadge('authenticate', $csrfToken), ]
);
}
public function onAuthenticationSuccess(Request $request, TokenInterface $token, string $firewallName): ?Response
{
// on success, let the request continue
//设置session 店铺 TODO
return new RedirectResponse($this->router->generate('admin_auth.admin'));
}
}