Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion appsec/src/extension/php_helpers.c
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,7 @@ const zend_array *nonnull dd_get_superglob_or_equiv(
if (equiv) {
ret = zend_hash_str_find(equiv, name, name_len);
} else {
ret = dd_php_get_autoglobal(track, ZEND_STRL("_GET"));
ret = dd_php_get_autoglobal(track, name, name_len);
}

if (!ret || Z_TYPE_P(ret) != IS_ARRAY) {
Expand Down
90 changes: 69 additions & 21 deletions src/DDTrace/Integrations/Laravel/LaravelIntegration.php
Original file line number Diff line number Diff line change
Expand Up @@ -367,27 +367,38 @@ static function ($This, $scope, $args, $loginSuccess) {
static function ($This, $scope, $args) {
$authClass = 'Illuminate\Contracts\Auth\Authenticatable';
if (
!function_exists('\datadog\appsec\track_user_login_success_event_automated') ||
!function_exists('datadog\appsec\track_user_login_success_event_automated') ||
!isset($args[1]) ||
!$args[1] ||
!($args[1] instanceof $authClass)
) {
return;
}

$user = $args[1];
$metadata = [];

if (isset($args[1]['name'])) {
$metadata['name'] = $args[1]['name'];
}

if (isset($args[1]['email'])) {
$metadata['email'] = $args[1]['email'];
if (\method_exists($user, '__isset') && \method_exists($user, '__get')) {
// Model methods have table columns as properties
if (isset($user->name)) {
$metadata['name'] = $user->name;
}
if (isset($user->email)) {
$metadata['email'] = $user->email;
}
} elseif ($user instanceof \ArrayAccess) {
// Model also implements ArrayAccess
if (isset($user['name'])) {
$metadata['name'] = $user['name'];
}
if (isset($user['email'])) {
$metadata['email'] = $user['email'];
}
}

\datadog\appsec\track_user_login_success_event_automated(
self::getLoginFromArgs($args[1]),
\method_exists($args[1], 'getAuthIdentifier') ? $args[1]->getAuthIdentifier() : '',
self::getLoginFromArgs($user),
self::getAuthIdentifier($user),
$metadata
);
}
Expand Down Expand Up @@ -420,7 +431,7 @@ static function ($This, $scope, $args) {

\datadog\appsec\track_user_login_success_event_automated(
self::getLoginFromArgs($args[0]),
\method_exists($args[0], 'getAuthIdentifier') ? $args[0]->getAuthIdentifier() : '',
self::getAuthIdentifier($args[0]),
$metadata
);
}
Expand Down Expand Up @@ -454,13 +465,14 @@ static function ($This, $scope, $args, $user) {
if (
!isset($user) ||
!$user ||
!($user instanceof $authClass) ||
!\method_exists($user, 'getAuthIdentifier')
!($user instanceof $authClass)
) {
return;
}

\datadog\appsec\track_authenticated_user_event_automated($user->getAuthIdentifier());
\datadog\appsec\track_authenticated_user_event_automated(
self::getAuthIdentifier($user)
);
}
);

Expand All @@ -478,13 +490,14 @@ static function ($This, $scope, $args) {
if (
!isset($args[1]) ||
!$args[1] ||
!($args[1] instanceof $authClass) ||
!\method_exists($args[1], 'getAuthIdentifier')
!($args[1] instanceof $authClass)
) {
return;
}

\datadog\appsec\track_authenticated_user_event_automated($args[1]->getAuthIdentifier());
\datadog\appsec\track_authenticated_user_event_automated(
self::getAuthIdentifier($args[1])
);
}
);

Expand All @@ -505,7 +518,7 @@ static function ($This, $scope, $args) {

\datadog\appsec\track_user_signup_event_automated(
self::getLoginFromArgs($args[0]),
\method_exists($args[0], 'getAuthIdentifier') ? $args[0]->getAuthIdentifier() : '',
self::getAuthIdentifier($args[0]),
[]
);
}
Expand Down Expand Up @@ -588,16 +601,51 @@ public static function getServiceName()
*/
public static function getLoginFromArgs($args)
{
if (isset($args['email'])) {
return $args['email'];
if (\is_array($args) || $args instanceof \ArrayAccess) {
if (isset($args['email'])) {
return $args['email'];
}
if (isset($args['username'])) {
return $args['username'];
}
}

if (!\is_object($args)) {
return null;
}

if (isset($args->email)) {
return $args->email;
}
if (isset($args['username'])) {
return $args['username'];

if (isset($args->username)) {
return $args->username;
}

$clazz = 'Illuminate\Auth\Passwords\CanResetPassword';
if ($args instanceof $clazz) {
return $args->getEmailForPasswordReset();
}

return null;
}

public static function getAuthIdentifier($user)
{
if (!\is_object($user) || !\method_exists($user, "getAuthIdentifier")) {
return '';
}

$identifier = $user->getAuthIdentifier();
if (\is_string($identifier)) {
return $identifier;
}
if (\is_int($identifier)) {
return (string)$identifier;
}
return ''; // could be an aggregate key?
}

/**
* Tells whether a span is a lumen request.
*
Expand Down
Loading