From 51370a8ed99417b2a5c7b0879dc207ebf956f086 Mon Sep 17 00:00:00 2001 From: klsoft-web Date: Wed, 26 Aug 2026 09:58:03 +0300 Subject: [PATCH] Remove AuthenticationMethodInterface and challenge() methods in classes that not implement AuthenticatorWithChallengeInterface --- CHANGELOG.md | 4 ++-- config/params.php | 6 +++--- src/AuthenticationMethodInterface.php | 11 ----------- ...> AuthenticatorWithChallengeInterfaceProxy.php} | 9 +++------ src/Method/Composite.php | 5 +---- src/Method/HttpBasic.php | 5 +---- src/Method/HttpCookie.php | 14 +------------- src/Method/HttpHeader.php | 14 +------------- src/Method/QueryParameter.php | 14 +------------- src/Middleware/Authentication.php | 3 +-- tests/AuthenticationMiddlewareTest.php | 8 ++++---- tests/Method/HttpCookieTest.php | 9 --------- tests/Method/HttpHeaderTest.php | 14 -------------- tests/Method/QueryParameterTest.php | 11 ----------- 14 files changed, 18 insertions(+), 109 deletions(-) delete mode 100644 src/AuthenticationMethodInterface.php rename src/Debug/{AuthenticationMethodInterfaceProxy.php => AuthenticatorWithChallengeInterfaceProxy.php} (66%) diff --git a/CHANGELOG.md b/CHANGELOG.md index b1aea45..2aa310f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,8 +1,8 @@ # Yii Auth Change Log -## 3.3.2 under development +## 4.0.0 under development -- no changes in this release. +- Enh #122: Remove AuthenticationMethodInterface and challenge() methods in classes that not implement AuthenticatorWithChallengeInterface (@klsoft-web) ## 3.3.1 August 11, 2026 diff --git a/config/params.php b/config/params.php index aa5d898..7c57855 100644 --- a/config/params.php +++ b/config/params.php @@ -2,8 +2,8 @@ declare(strict_types=1); -use Yiisoft\Auth\AuthenticationMethodInterface; -use Yiisoft\Auth\Debug\AuthenticationMethodInterfaceProxy; +use Yiisoft\Auth\AuthenticatorWithChallengeInterface; +use Yiisoft\Auth\Debug\AuthenticatorWithChallengeInterfaceProxy; use Yiisoft\Auth\Debug\IdentityCollector; return [ @@ -12,7 +12,7 @@ IdentityCollector::class, ], 'trackedServices' => [ - AuthenticationMethodInterface::class => [AuthenticationMethodInterfaceProxy::class, IdentityCollector::class], + AuthenticatorWithChallengeInterface::class => [AuthenticatorWithChallengeInterfaceProxy::class, IdentityCollector::class], ], ], ]; diff --git a/src/AuthenticationMethodInterface.php b/src/AuthenticationMethodInterface.php deleted file mode 100644 index adeb27a..0000000 --- a/src/AuthenticationMethodInterface.php +++ /dev/null @@ -1,11 +0,0 @@ -identityRepository->findIdentityByToken($authToken, $this->tokenType); } - /** - * @deprecated No-op kept only for compatibility with the deprecated {@see AuthenticationMethodInterface}. - * HTTP cookie authentication does not need a challenge. - */ - public function challenge(ResponseInterface $response): ResponseInterface - { - return $response; - } - /** * @psalm-immutable */ diff --git a/src/Method/HttpHeader.php b/src/Method/HttpHeader.php index 4e81c30..719b124 100644 --- a/src/Method/HttpHeader.php +++ b/src/Method/HttpHeader.php @@ -7,7 +7,6 @@ use JetBrains\PhpStorm\Language; use Psr\Http\Message\ResponseInterface; use Psr\Http\Message\ServerRequestInterface; -use Yiisoft\Auth\AuthenticationMethodInterface; use Yiisoft\Auth\AuthenticatorInterface; use Yiisoft\Auth\IdentityInterface; use Yiisoft\Auth\IdentityWithTokenRepositoryInterface; @@ -20,10 +19,8 @@ * The default implementation of HttpHeader uses the * {@see IdentityWithTokenRepositoryInterface::findIdentityByToken()} * and passes the value of the `X-Api-Key` header. This implementation is used mainly for authenticating API clients. - * - * @psalm-suppress DeprecatedInterface */ -class HttpHeader implements AuthenticationMethodInterface, AuthenticatorInterface +class HttpHeader implements AuthenticatorInterface { protected string $headerName = 'X-Api-Key'; @@ -46,15 +43,6 @@ public function authenticate(ServerRequestInterface $request): ?IdentityInterfac return null; } - /** - * @deprecated No-op kept only for compatibility with the deprecated {@see AuthenticationMethodInterface}. - * HTTP header authentication does not need a challenge. - */ - public function challenge(ResponseInterface $response): ResponseInterface - { - return $response; - } - /** * @param string $name The HTTP header name. * diff --git a/src/Method/QueryParameter.php b/src/Method/QueryParameter.php index e21ac97..00ec6bc 100644 --- a/src/Method/QueryParameter.php +++ b/src/Method/QueryParameter.php @@ -6,7 +6,6 @@ use Psr\Http\Message\ResponseInterface; use Psr\Http\Message\ServerRequestInterface; -use Yiisoft\Auth\AuthenticationMethodInterface; use Yiisoft\Auth\AuthenticatorInterface; use Yiisoft\Auth\IdentityInterface; use Yiisoft\Auth\IdentityWithTokenRepositoryInterface; @@ -15,10 +14,8 @@ /** * QueryParameter supports the authentication based on the access token passed through a query parameter. - * - * @psalm-suppress DeprecatedInterface */ -final class QueryParameter implements AuthenticationMethodInterface, AuthenticatorInterface +final class QueryParameter implements AuthenticatorInterface { private string $parameterName = 'access-token'; private ?string $tokenType = null; @@ -35,15 +32,6 @@ public function authenticate(ServerRequestInterface $request): ?IdentityInterfac return null; } - /** - * @deprecated No-op kept only for compatibility with the deprecated {@see AuthenticationMethodInterface}. - * Query parameter authentication does not need a challenge. - */ - public function challenge(ResponseInterface $response): ResponseInterface - { - return $response; - } - /** * @param string $name The parameter name for passing the access token. * diff --git a/src/Middleware/Authentication.php b/src/Middleware/Authentication.php index cfcb9bf..0db017d 100644 --- a/src/Middleware/Authentication.php +++ b/src/Middleware/Authentication.php @@ -9,7 +9,6 @@ use Psr\Http\Message\ServerRequestInterface; use Psr\Http\Server\MiddlewareInterface; use Psr\Http\Server\RequestHandlerInterface; -use Yiisoft\Auth\AuthenticationMethodInterface; use Yiisoft\Auth\AuthenticatorInterface; use Yiisoft\Auth\AuthenticatorWithChallengeInterface; use Yiisoft\Auth\Handler\AuthenticationFailureHandler; @@ -37,7 +36,7 @@ final class Authentication implements MiddlewareInterface private array $wildcards = []; public function __construct( - private AuthenticatorInterface|AuthenticationMethodInterface $authenticationMethod, + private AuthenticatorInterface $authenticationMethod, ResponseFactoryInterface $responseFactory, ?RequestHandlerInterface $authenticationFailureHandler = null, ) { diff --git a/tests/AuthenticationMiddlewareTest.php b/tests/AuthenticationMiddlewareTest.php index 192152e..8e3db0c 100644 --- a/tests/AuthenticationMiddlewareTest.php +++ b/tests/AuthenticationMiddlewareTest.php @@ -13,8 +13,8 @@ use Psr\Http\Message\ResponseInterface; use Psr\Http\Message\ServerRequestInterface; use Psr\Http\Server\RequestHandlerInterface; -use Yiisoft\Auth\AuthenticationMethodInterface; use Yiisoft\Auth\AuthenticatorInterface; +use Yiisoft\Auth\AuthenticatorWithChallengeInterface; use Yiisoft\Auth\IdentityInterface; use Yiisoft\Auth\Middleware\Authentication; use Yiisoft\Http\Status; @@ -23,13 +23,13 @@ final class AuthenticationMiddlewareTest extends TestCase { private ResponseFactoryInterface $responseFactory; - /** @var AuthenticationMethodInterface|MockObject */ - private AuthenticationMethodInterface $authenticationMethod; + /** @var AuthenticatorWithChallengeInterface|MockObject */ + private AuthenticatorWithChallengeInterface $authenticationMethod; protected function setUp(): void { $this->responseFactory = new Psr17Factory(); - $this->authenticationMethod = $this->createMock(AuthenticationMethodInterface::class); + $this->authenticationMethod = $this->createMock(AuthenticatorWithChallengeInterface::class); } public function testShouldAuthenticateAndSetAttribute(): void diff --git a/tests/Method/HttpCookieTest.php b/tests/Method/HttpCookieTest.php index 1b79007..04bce60 100644 --- a/tests/Method/HttpCookieTest.php +++ b/tests/Method/HttpCookieTest.php @@ -60,15 +60,6 @@ public function testIdentityNotFoundByToken(): void ); } - public function testChallengeImmutabilityStatus(): void - { - $response = new Response(400); - $identityRepository = new FakeIdentityRepository($this->createIdentity()); - $authenticationMethod = new HttpCookie($identityRepository); - - $this->assertSame($response, $authenticationMethod->challenge($response)); - } - public function testCustomTokenParam(): void { $identityRepository = new FakeIdentityRepository($this->createIdentity()); diff --git a/tests/Method/HttpHeaderTest.php b/tests/Method/HttpHeaderTest.php index 7759f45..a819140 100644 --- a/tests/Method/HttpHeaderTest.php +++ b/tests/Method/HttpHeaderTest.php @@ -39,20 +39,6 @@ public function testIdentityNotFoundByToken(): void ); } - public function testChallengeIsCorrect(): void - { - $response = new Response(400); - $identityRepository = new FakeIdentityRepository($this->createIdentity()); - $authenticationMethod = new HttpHeader($identityRepository); - - $this->assertEquals( - 400, - $authenticationMethod - ->challenge($response) - ->getStatusCode(), - ); - } - public function testEmptyTokenHeader(): void { $identityRepository = new FakeIdentityRepository($this->createIdentity()); diff --git a/tests/Method/QueryParameterTest.php b/tests/Method/QueryParameterTest.php index a97af9c..6934681 100644 --- a/tests/Method/QueryParameterTest.php +++ b/tests/Method/QueryParameterTest.php @@ -62,17 +62,6 @@ public function testInvalidTypeToken(): void $this->assertEmpty($identityRepository->getCallParams()); } - public function testChallengeIsCorrect(): void - { - $response = new Response(400); - $identityRepository = new FakeIdentityRepository($this->createIdentity()); - $authenticationMethod = new QueryParameter($identityRepository); - - $this->assertEquals(400, $authenticationMethod - ->challenge($response) - ->getStatusCode()); - } - public function testCustomTokenParam(): void { $identityRepository = new FakeIdentityRepository($this->createIdentity());