session = $session; } /** * Middleware set the token for the request * * @since 14.0.0 */ final public function setToken(string $token) { $this->token = $token; } /** * Get the token for this request * * @since 14.0.0 */ final public function getToken(): string { return $this->token; } /** * Get a hash of the password for this share * * To ensure access is blocked when the password to a share is changed we store * a hash of the password for this token. * * @since 14.0.0 */ abstract protected function getPasswordHash(): ?string; /** * Is the provided token a valid token * * This function is already called from the middleware directly after setting the token. * * @since 14.0.0 */ abstract public function isValidToken(): bool; /** * Is a share with this token password protected * * @since 14.0.0 */ abstract protected function isPasswordProtected(): bool; /** * Check if a share is authenticated or not * * @since 14.0.0 */ public function isAuthenticated(): bool { // Always authenticated against non password protected shares if (!$this->isPasswordProtected()) { return true; } // If we are authenticated properly if ($this->session->get('public_link_authenticated_token') === $this->getToken() && $this->session->get('public_link_authenticated_password_hash') === $this->getPasswordHash()) { return true; } // Fail by default if nothing matches return false; } /** * Function called if the share is not found. * * You can use this to do some logging for example * * @since 14.0.0 */ public function shareNotFound() { } }