LoginController
extends DefaultController
in package
Login Controller
Handles user login operations including form display, input validation, and authentication processing. Works with AuthController to verify user credentials and establish authenticated sessions.
Implements a conditional anti-brute-force mechanism: after 5 failed attempts from the same IP + email pair within 15 minutes, a Google reCAPTCHA v2 widget is shown and validated before credentials are checked.
Tags
Table of Contents
Constants
Properties
- $app : Application
- $auth : AuthManager
- $csrf : CsrfProtection
- $request : Request
- $response : Response
- $session : SessionManager
- $attemptManager : LoginAttemptManager
- $clientIp : string
- $isSuspect : bool
- $recaptchaValidator : RecaptchaValidator
Methods
- __construct() : mixed
- Constructor - Initialize the LoginController
- getCsrfTokenForJs() : string
- Get the CSRF token for JavaScript usage
- redirect() : never
- Redirect to a URL
- redirectWithError() : never
- Redirect with an error message
- redirectWithSuccess() : never
- Redirect with a success message
- render() : void
- Render a view with automatic variable injection
- setError() : void
- Set an error flash message
- setFlash() : void
- Set a flash message
- setInfo() : void
- Set an info flash message
- setSuccess() : void
- Set a success flash message
- setWarning() : void
- Set a warning flash message
- validateCsrf() : bool
- Validate the CSRF token from the request
- buildViewData() : array<string, mixed>
- Build the data array passed to the login view
- processLogin() : void
- Process the login form submission
Constants
ATTEMPT_THRESHOLD
private
mixed
ATTEMPT_THRESHOLD
= 5
Properties
$app
protected
Application
$app
$auth
protected
AuthManager
$auth
$csrf
protected
CsrfProtection
$csrf
$request
protected
Request
$request
$response
protected
Response
$response
$session
protected
SessionManager
$session
$attemptManager
private
LoginAttemptManager
$attemptManager
$clientIp
private
string
$clientIp
$isSuspect
private
bool
$isSuspect
$recaptchaValidator
private
RecaptchaValidator
$recaptchaValidator
Methods
__construct()
Constructor - Initialize the LoginController
public
__construct() : mixed
Resolves the client IP, checks the failed-attempt count, then either displays the login form or processes the submission.
getCsrfTokenForJs()
Get the CSRF token for JavaScript usage
protected
getCsrfTokenForJs() : string
This method is useful for embedding the token in JavaScript or as a meta tag for automatic AJAX injection.
Return values
string —The current CSRF token
redirect()
Redirect to a URL
protected
redirect(string $url) : never
Parameters
- $url : string
-
Destination URL
Return values
never —Terminates execution
redirectWithError()
Redirect with an error message
protected
redirectWithError(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Error message
Return values
never —Terminates execution
redirectWithSuccess()
Redirect with a success message
protected
redirectWithSuccess(string $url, string $message) : never
Parameters
- $url : string
-
Destination URL
- $message : string
-
Success message
Return values
never —Terminates execution
render()
Render a view with automatic variable injection
protected
render(string $viewPath[, array<string, mixed> $data = [] ]) : void
This method automatically injects services and data that all views need, eliminating the need to directly access $_SESSION or global functions.
Automatically injected variables:
- $csrf: CsrfProtection service
- $auth: AuthManager service
- $request: Request object
- $flash: Flash messages array (success, error, warning, info)
- $user: Current user data (null if not logged in)
Parameters
- $viewPath : string
-
View path (e.g., 'users/loginPageView')
- $data : array<string, mixed> = []
-
View-specific data
setError()
Set an error flash message
protected
setError(string $message) : void
Parameters
- $message : string
-
Error message
setFlash()
Set a flash message
protected
setFlash(string $type, string $message) : void
Parameters
- $type : string
-
Message type (success, error, warning, info)
- $message : string
-
Message to display
setInfo()
Set an info flash message
protected
setInfo(string $message) : void
Parameters
- $message : string
-
Info message
setSuccess()
Set a success flash message
protected
setSuccess(string $message) : void
Parameters
- $message : string
-
Success message
setWarning()
Set a warning flash message
protected
setWarning(string $message) : void
Parameters
- $message : string
-
Warning message
validateCsrf()
Validate the CSRF token from the request
protected
validateCsrf([string|null $token = null ]) : bool
Supports both traditional POST body tokens and modern AJAX header tokens. Checks in order:
- Provided token parameter
- POST body 'csrf_token' field
- X-CSRF-Token HTTP header (for AJAX requests)
Parameters
- $token : string|null = null
-
Token to validate (if null, retrieves from POST or header)
Return values
bool —True if valid, false otherwise
buildViewData()
Build the data array passed to the login view
private
buildViewData() : array<string, mixed>
Return values
array<string, mixed>processLogin()
Process the login form submission
private
processLogin() : void
Validates CSRF token, optionally validates reCAPTCHA, verifies credentials, and on success establishes the authenticated session. On failure, records the attempt and updates the suspect flag for the view.