ValidateTeamInvitationController
extends DefaultController
in package
ValidateTeamInvitationController - Team Invitation Validation
Handles the validation of team invitations via email link. Users click on the link in their email to confirm or decline their participation.
Features:
- Validate invitation tokens
- Confirm or decline participation
- Automatically confirm team when all members validated
- Register confirmed teams to the event
Tags
Table of Contents
Properties
- $app : Application
- $auth : AuthManager
- $csrf : CsrfProtection
- $request : Request
- $response : Response
- $session : SessionManager
- $invitationRepo : EventTeamInvitationRepository
- Invitation repository instance
- $registrationRepo : EventRegistrationRepository
- Registration repository instance
- $teamRepo : EventTeamRepository
- Team repository instance
Methods
- __construct() : void
- Constructor - Handle invitation validation
- getCsrfTokenForJs() : string
- Get the CSRF token for JavaScript usage
- redirect() : never
- Redirect to a URL
- redirectWithError() : never
- Redirect with an error message
- redirectWithSuccess() : never
- Redirect with a success message
- render() : void
- Render a view with automatic variable injection
- setError() : void
- Set an error flash message
- setFlash() : void
- Set a flash message
- setInfo() : void
- Set an info flash message
- setSuccess() : void
- Set a success flash message
- setWarning() : void
- Set a warning flash message
- validateCsrf() : bool
- Validate the CSRF token from the request
- confirmInvitation() : void
- Confirm the invitation
- declineInvitation() : void
- Decline the invitation
- displayInvitation() : void
- Display the invitation details for the user to confirm or decline
- notifyTeamCreator() : void
- Send notification email to the team creator
- registerTeamMembers() : void
- Register all confirmed team members to the event
Properties
$app
protected
Application
$app
$auth
protected
AuthManager
$auth
$csrf
protected
CsrfProtection
$csrf
$request
protected
Request
$request
$response
protected
Response
$response
$session
protected
SessionManager
$session
$invitationRepo
Invitation repository instance
private
EventTeamInvitationRepository
$invitationRepo
$registrationRepo
Registration repository instance
private
EventRegistrationRepository
$registrationRepo
$teamRepo
Team repository instance
private
EventTeamRepository
$teamRepo
Methods
__construct()
Constructor - Handle invitation validation
public
__construct() : void
Supports actions via GET parameter:
- Default: Display invitation details
- confirm: Confirm participation
- decline: Decline participation
getCsrfTokenForJs()
Get the CSRF token for JavaScript usage
protected
getCsrfTokenForJs() : string
This method is useful for embedding the token in JavaScript or as a meta tag for automatic AJAX injection.
Return values
string —The current CSRF token
redirect()
Redirect to a URL
protected
redirect(string $url) : never
Parameters
- $url : string
-
Destination URL
Return values
never —Terminates execution
redirectWithError()
Redirect with an error message
protected
redirectWithError(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Error message
Return values
never —Terminates execution
redirectWithSuccess()
Redirect with a success message
protected
redirectWithSuccess(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Success message
Return values
never —Terminates execution
render()
Render a view with automatic variable injection
protected
render(string $viewPath[, array<string, mixed> $data = [] ]) : void
This method automatically injects services and data that all views need, eliminating the need to directly access $_SESSION or global functions.
Automatically injected variables:
- $csrf: CsrfProtection service
- $auth: AuthManager service
- $request: Request object
- $flash: Flash messages array (success, error, warning, info)
- $user: Current user data (null if not logged in)
Parameters
- $viewPath : string
-
View path (e.g., 'users/loginPageView')
- $data : array<string, mixed> = []
-
View-specific data
setError()
Set an error flash message
protected
setError(string $message) : void
Parameters
- $message : string
-
Error message
setFlash()
Set a flash message
protected
setFlash(string $type, string $message) : void
Parameters
- $type : string
-
Message type (success, error, warning, info)
- $message : string
-
Message to display
setInfo()
Set an info flash message
protected
setInfo(string $message) : void
Parameters
- $message : string
-
Info message
setSuccess()
Set a success flash message
protected
setSuccess(string $message) : void
Parameters
- $message : string
-
Success message
setWarning()
Set a warning flash message
protected
setWarning(string $message) : void
Parameters
- $message : string
-
Warning message
validateCsrf()
Validate the CSRF token from the request
protected
validateCsrf([string|null $token = null ]) : bool
Supports both traditional POST body tokens and modern AJAX header tokens. Checks in order:
- Provided token parameter
- POST body 'csrf_token' field
- X-CSRF-Token HTTP header (for AJAX requests)
Parameters
- $token : string|null = null
-
Token to validate (if null, retrieves from POST or header)
Return values
bool —True if valid, false otherwise
confirmInvitation()
Confirm the invitation
private
confirmInvitation(array<string, mixed> $invitation, string $token) : void
Parameters
- $invitation : array<string, mixed>
-
Invitation data
- $token : string
-
The validation token
declineInvitation()
Decline the invitation
private
declineInvitation(array<string, mixed> $invitation, string $token) : void
Parameters
- $invitation : array<string, mixed>
-
Invitation data
- $token : string
-
The validation token
displayInvitation()
Display the invitation details for the user to confirm or decline
private
displayInvitation(array<string, mixed> $invitation, string $token) : void
Parameters
- $invitation : array<string, mixed>
-
Invitation data
- $token : string
-
The validation token
notifyTeamCreator()
Send notification email to the team creator
private
notifyTeamCreator(int $teamId) : void
Retrieves team and creator info, then sends an email notifying the creator that all members have confirmed.
Parameters
- $teamId : int
-
The team identifier
registerTeamMembers()
Register all confirmed team members to the event
private
registerTeamMembers(int $teamId, int $eventId) : void
Parameters
- $teamId : int
-
The team identifier
- $eventId : int
-
The event identifier