vendor/api-platform/core/src/Symfony/EventListener/QueryParameterValidateListener.php line 62

Open in your IDE?
  1. <?php
  2. /*
  3.  * This file is part of the API Platform project.
  4.  *
  5.  * (c) Kévin Dunglas <dunglas@gmail.com>
  6.  *
  7.  * For the full copyright and license information, please view the LICENSE
  8.  * file that was distributed with this source code.
  9.  */
  10. declare(strict_types=1);
  11. namespace ApiPlatform\Symfony\EventListener;
  12. use ApiPlatform\Api\QueryParameterValidator\QueryParameterValidator;
  13. use ApiPlatform\Core\Filter\QueryParameterValidator as LegacyQueryParameterValidator;
  14. use ApiPlatform\Core\Metadata\Resource\Factory\ResourceMetadataFactoryInterface;
  15. use ApiPlatform\Core\Metadata\Resource\ToggleableOperationAttributeTrait;
  16. use ApiPlatform\Metadata\CollectionOperationInterface;
  17. use ApiPlatform\Metadata\Resource\Factory\ResourceMetadataCollectionFactoryInterface;
  18. use ApiPlatform\Util\OperationRequestInitiatorTrait;
  19. use ApiPlatform\Util\RequestAttributesExtractor;
  20. use ApiPlatform\Util\RequestParser;
  21. use Symfony\Component\HttpKernel\Event\RequestEvent;
  22. /**
  23.  * Validates query parameters depending on filter description.
  24.  *
  25.  * @author Julien Deniau <julien.deniau@mapado.com>
  26.  */
  27. final class QueryParameterValidateListener
  28. {
  29.     use OperationRequestInitiatorTrait;
  30.     use ToggleableOperationAttributeTrait;
  31.     public const OPERATION_ATTRIBUTE_KEY 'query_parameter_validate';
  32.     private $resourceMetadataFactory;
  33.     private $queryParameterValidator;
  34.     private $enabled;
  35.     /**
  36.      * @param ResourceMetadataCollectionFactoryInterface|ResourceMetadataFactoryInterface $resourceMetadataFactory
  37.      * @param QueryParameterValidator|LegacyQueryParameterValidator                       $queryParameterValidator
  38.      */
  39.     public function __construct($resourceMetadataFactory$queryParameterValidatorbool $enabled true)
  40.     {
  41.         if (!$resourceMetadataFactory instanceof ResourceMetadataCollectionFactoryInterface) {
  42.             trigger_deprecation('api-platform/core''2.7'sprintf('Use "%s" instead of "%s".'ResourceMetadataCollectionFactoryInterface::class, ResourceMetadataFactoryInterface::class));
  43.         } else {
  44.             $this->resourceMetadataCollectionFactory $resourceMetadataFactory;
  45.         }
  46.         $this->resourceMetadataFactory $resourceMetadataFactory;
  47.         $this->queryParameterValidator $queryParameterValidator;
  48.         $this->enabled $enabled;
  49.     }
  50.     public function onKernelRequest(RequestEvent $event)
  51.     {
  52.         $request $event->getRequest();
  53.         $operation $this->initializeOperation($request);
  54.         if (
  55.             !$request->isMethodSafe()
  56.             || !($attributes RequestAttributesExtractor::extractAttributes($request))
  57.             || 'GET' !== $request->getMethod()
  58.         ) {
  59.             return;
  60.         }
  61.         if ($this->resourceMetadataFactory instanceof ResourceMetadataCollectionFactoryInterface
  62.             && (!$operation || !($operation->getQueryParameterValidationEnabled() ?? true) || !$operation instanceof CollectionOperationInterface)
  63.         ) {
  64.             return;
  65.         }
  66.         // TODO: remove in 3.0
  67.         $operationName $attributes['collection_operation_name'] ?? null;
  68.         if (!$this->resourceMetadataFactory instanceof ResourceMetadataCollectionFactoryInterface
  69.             && (
  70.                 null === $operationName
  71.                 || $this->isOperationAttributeDisabled($attributesself::OPERATION_ATTRIBUTE_KEY, !$this->enabled)
  72.             )
  73.         ) {
  74.             return;
  75.         }
  76.         $queryString RequestParser::getQueryString($request);
  77.         $queryParameters $queryString RequestParser::parseRequestParams($queryString) : [];
  78.         $resourceFilters = [];
  79.         if ($this->resourceMetadataFactory instanceof ResourceMetadataFactoryInterface) {
  80.             $resourceFilters $this->resourceMetadataFactory->create($attributes['resource_class'])->getCollectionOperationAttribute($operationName'filters', [], true);
  81.         } elseif ($operation) {
  82.             $resourceFilters $operation->getFilters() ?? [];
  83.         }
  84.         $this->queryParameterValidator->validateFilters($attributes['resource_class'], $resourceFilters$queryParameters);
  85.     }
  86. }
  87. class_alias(QueryParameterValidateListener::class, \ApiPlatform\Core\EventListener\QueryParameterValidateListener::class);