feat: add team editor GET and POST handlers
This commit is contained in:
@@ -0,0 +1,29 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace BattleForge\Http\Handlers;
|
||||||
|
|
||||||
|
use BattleForge\Http\Request;
|
||||||
|
use BattleForge\Http\Response;
|
||||||
|
|
||||||
|
final class GetTeamEditor
|
||||||
|
{
|
||||||
|
/** @param array<string, string> $params */
|
||||||
|
public function handle(Request $request, array $params): Response
|
||||||
|
{
|
||||||
|
$csrf = $request->cookies['__csrf'] ?? '';
|
||||||
|
$scenarioId = $params['id'] ?? 'new';
|
||||||
|
|
||||||
|
$error = null;
|
||||||
|
$old = [];
|
||||||
|
$post = [];
|
||||||
|
|
||||||
|
ob_start();
|
||||||
|
require_once __DIR__ . '/../../Views/layout.php';
|
||||||
|
require __DIR__ . '/../../Views/team-editor.php';
|
||||||
|
$body = (string) ob_get_clean();
|
||||||
|
|
||||||
|
return Response::html(200, $body);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,86 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace BattleForge\Http\Handlers;
|
||||||
|
|
||||||
|
use BattleForge\Application\ScenarioDraft;
|
||||||
|
use BattleForge\Domain\ScenarioValidator;
|
||||||
|
use BattleForge\Http\CsrfToken;
|
||||||
|
use BattleForge\Http\Escape;
|
||||||
|
use BattleForge\Http\Request;
|
||||||
|
use BattleForge\Http\Response;
|
||||||
|
|
||||||
|
final class PostTeamEditor
|
||||||
|
{
|
||||||
|
/** @param array<string, string> $params */
|
||||||
|
public function handle(Request $request, array $params): Response
|
||||||
|
{
|
||||||
|
$submitted = (string) ($request->post['_csrf'] ?? '');
|
||||||
|
$expected = (string) ($request->cookies['__csrf'] ?? '');
|
||||||
|
$secret = (string) ($request->server['__csrf_secret'] ?? '');
|
||||||
|
|
||||||
|
if ($secret === '' || $expected === '' || !CsrfToken::verify($submitted, $secret, $expected)) {
|
||||||
|
return Response::html(403, '<h1>Forbidden</h1>');
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
$draft = ScenarioDraft::fromPost($request->post);
|
||||||
|
$scenario = $draft->toScenario();
|
||||||
|
ScenarioValidator::validate($scenario);
|
||||||
|
} catch (\InvalidArgumentException $exception) {
|
||||||
|
return $this->renderForm($request, $params['id'] ?? 'new', $request->cookies['__csrf'] ?? '', $exception->getMessage(), $request->post);
|
||||||
|
}
|
||||||
|
|
||||||
|
$json = json_encode($this->scenarioToArray($scenario), JSON_THROW_ON_ERROR);
|
||||||
|
$url = (string) ($params['id'] ?? $scenario->id);
|
||||||
|
$body = <<<HTML
|
||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
<head><meta charset="utf-8"><title>Saved</title></head>
|
||||||
|
<body>
|
||||||
|
<p>Scenario saved.</p>
|
||||||
|
<script type="module">
|
||||||
|
localStorage.setItem('scenario:{$url}', $json);
|
||||||
|
</script>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
|
HTML;
|
||||||
|
|
||||||
|
return Response::html(200, $body);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param array<string, mixed> $post */
|
||||||
|
private function renderForm(Request $request, string $scenarioId, string $csrf, string $error, array $post): Response
|
||||||
|
{
|
||||||
|
$error = Escape::html($error);
|
||||||
|
$csrf = Escape::html($csrf);
|
||||||
|
$scenarioId = Escape::html($scenarioId);
|
||||||
|
|
||||||
|
$old = array_intersect_key($post, array_flip([
|
||||||
|
'id',
|
||||||
|
'name',
|
||||||
|
'battlefieldWidth',
|
||||||
|
'battlefieldHeight',
|
||||||
|
'victoryCondition',
|
||||||
|
'holdRoundsRequired',
|
||||||
|
]));
|
||||||
|
$old = array_map(static fn ($v): string => is_scalar($v) ? (string) $v : '', $old);
|
||||||
|
|
||||||
|
$teamA = $post['teamA']['units'] ?? [];
|
||||||
|
$teamB = $post['teamB']['units'] ?? [];
|
||||||
|
|
||||||
|
ob_start();
|
||||||
|
require_once __DIR__ . '/../../Views/layout.php';
|
||||||
|
require __DIR__ . '/../../Views/team-editor.php';
|
||||||
|
$body = (string) ob_get_clean();
|
||||||
|
|
||||||
|
return Response::html(200, $body);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @return array<string, mixed> */
|
||||||
|
private function scenarioToArray(\BattleForge\Domain\Scenario $scenario): array
|
||||||
|
{
|
||||||
|
return \BattleForge\Application\ScenarioSerializer::scenarioToArray($scenario);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace BattleForge\Tests\Integration;
|
||||||
|
|
||||||
|
use BattleForge\Http\Handlers\GetTeamEditor;
|
||||||
|
use BattleForge\Http\Request;
|
||||||
|
use PHPUnit\Framework\TestCase;
|
||||||
|
|
||||||
|
final class GetTeamEditorTest extends TestCase
|
||||||
|
{
|
||||||
|
public function testItReturnsTheTeamEditorPageWithSecurityHeaders(): void
|
||||||
|
{
|
||||||
|
$handler = new GetTeamEditor();
|
||||||
|
$request = new Request([], [], [], [], [], '', 'GET', '/scenarios/demo/edit/team', 'text/html', '');
|
||||||
|
|
||||||
|
$response = $handler->handle($request, ['id' => 'demo']);
|
||||||
|
|
||||||
|
self::assertSame(200, $response->status);
|
||||||
|
self::assertStringContainsString('text/html', $response->headers['Content-Type'] ?? '');
|
||||||
|
self::assertSame('nosniff', $response->headers['X-Content-Type-Options']);
|
||||||
|
self::assertStringContainsString('default-src', $response->headers['Content-Security-Policy']);
|
||||||
|
self::assertStringContainsString('name="_csrf"', $response->body);
|
||||||
|
self::assertStringContainsString('name="id"', $response->body);
|
||||||
|
self::assertStringContainsString('name="victoryCondition"', $response->body);
|
||||||
|
self::assertStringContainsString('value="defender"', $response->body);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,107 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace BattleForge\Tests\Integration;
|
||||||
|
|
||||||
|
use BattleForge\Domain\Archetype;
|
||||||
|
use BattleForge\Http\CsrfToken;
|
||||||
|
use BattleForge\Http\Handlers\PostTeamEditor;
|
||||||
|
use BattleForge\Http\Request;
|
||||||
|
use PHPUnit\Framework\TestCase;
|
||||||
|
|
||||||
|
final class PostTeamEditorTest extends TestCase
|
||||||
|
{
|
||||||
|
private const SECRET = 'unit-test-secret';
|
||||||
|
|
||||||
|
public function testItRejectsARequestWithAMissingCsrfToken(): void
|
||||||
|
{
|
||||||
|
$handler = new PostTeamEditor();
|
||||||
|
$request = $this->buildRequest(post: ['id' => 'demo']);
|
||||||
|
$response = $handler->handle($request, ['id' => 'demo']);
|
||||||
|
|
||||||
|
self::assertSame(403, $response->status);
|
||||||
|
self::assertStringContainsString('Forbidden', $response->body);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function testItRejectsARequestWithAnInvalidCsrfToken(): void
|
||||||
|
{
|
||||||
|
$handler = new PostTeamEditor();
|
||||||
|
$request = $this->buildRequest(post: ['id' => 'demo', '_csrf' => 'tampered']);
|
||||||
|
$response = $handler->handle($request, ['id' => 'demo']);
|
||||||
|
|
||||||
|
self::assertSame(403, $response->status);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function testItSavesAValidScenarioAndReturnsTheLocalStorageSnippet(): void
|
||||||
|
{
|
||||||
|
[$token, $cookie] = CsrfToken::issue(self::SECRET);
|
||||||
|
$handler = new PostTeamEditor();
|
||||||
|
$request = $this->buildRequest(
|
||||||
|
post: $this->validPost($token),
|
||||||
|
cookies: ['__csrf' => $cookie],
|
||||||
|
server: ['__csrf_secret' => self::SECRET],
|
||||||
|
);
|
||||||
|
$response = $handler->handle($request, ['id' => 'demo']);
|
||||||
|
|
||||||
|
self::assertSame(200, $response->status);
|
||||||
|
self::assertStringContainsString('localStorage.setItem', $response->body);
|
||||||
|
self::assertStringContainsString('scenario:demo', $response->body);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function testItRejectsAnOutOfBoundsStatAndReRendersTheForm(): void
|
||||||
|
{
|
||||||
|
[$token, $cookie] = CsrfToken::issue(self::SECRET);
|
||||||
|
$handler = new PostTeamEditor();
|
||||||
|
$post = $this->validPost($token);
|
||||||
|
$post['teamA']['units'][0]['maxHealth'] = '9999';
|
||||||
|
$request = $this->buildRequest(
|
||||||
|
post: $post,
|
||||||
|
cookies: ['__csrf' => $cookie],
|
||||||
|
server: ['__csrf_secret' => self::SECRET],
|
||||||
|
);
|
||||||
|
$response = $handler->handle($request, ['id' => 'demo']);
|
||||||
|
|
||||||
|
self::assertSame(200, $response->status);
|
||||||
|
self::assertStringContainsString('bf-errors', $response->body);
|
||||||
|
self::assertStringContainsString('outside archetype bounds', $response->body);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $post
|
||||||
|
* @param array<string, string> $cookies
|
||||||
|
* @param array<string, string> $server
|
||||||
|
*/
|
||||||
|
private function buildRequest(array $post, array $cookies = [], array $server = []): Request
|
||||||
|
{
|
||||||
|
return new Request([], $post, [], $cookies, $server, '', 'POST', '/scenarios/demo/edit/team', 'application/x-www-form-urlencoded', '');
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @return array<string, mixed> */
|
||||||
|
private function validPost(string $token): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
'_csrf' => $token,
|
||||||
|
'id' => 'demo',
|
||||||
|
'name' => 'Demo',
|
||||||
|
'battlefieldWidth' => '8',
|
||||||
|
'battlefieldHeight' => '8',
|
||||||
|
'teamA' => [
|
||||||
|
'units' => [
|
||||||
|
['id' => 'a1', 'archetype' => 'defender', 'maxHealth' => '12', 'attack' => '3', 'defense' => '4', 'speed' => '2', 'x' => '0', 'y' => '0'],
|
||||||
|
['id' => 'a2', 'archetype' => 'defender', 'maxHealth' => '12', 'attack' => '3', 'defense' => '4', 'speed' => '2', 'x' => '1', 'y' => '0'],
|
||||||
|
['id' => 'a3', 'archetype' => 'defender', 'maxHealth' => '12', 'attack' => '3', 'defense' => '4', 'speed' => '2', 'x' => '2', 'y' => '0'],
|
||||||
|
],
|
||||||
|
],
|
||||||
|
'teamB' => [
|
||||||
|
'units' => [
|
||||||
|
['id' => 'b1', 'archetype' => 'striker', 'maxHealth' => '8', 'attack' => '5', 'defense' => '2', 'speed' => '3', 'x' => '7', 'y' => '7'],
|
||||||
|
['id' => 'b2', 'archetype' => 'striker', 'maxHealth' => '8', 'attack' => '5', 'defense' => '2', 'speed' => '3', 'x' => '6', 'y' => '7'],
|
||||||
|
['id' => 'b3', 'archetype' => 'striker', 'maxHealth' => '8', 'attack' => '5', 'defense' => '2', 'speed' => '3', 'x' => '5', 'y' => '7'],
|
||||||
|
],
|
||||||
|
],
|
||||||
|
'victoryCondition' => 'eliminate_all',
|
||||||
|
'holdRoundsRequired' => '1',
|
||||||
|
];
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user