RequestDataCollector.php 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535
  1. <?php
  2. /*
  3. * This file is part of the Symfony package.
  4. *
  5. * (c) Fabien Potencier <fabien@symfony.com>
  6. *
  7. * For the full copyright and license information, please view the LICENSE
  8. * file that was distributed with this source code.
  9. */
  10. namespace Symfony\Component\HttpKernel\DataCollector;
  11. use Symfony\Component\EventDispatcher\EventSubscriberInterface;
  12. use Symfony\Component\HttpFoundation\Cookie;
  13. use Symfony\Component\HttpFoundation\ParameterBag;
  14. use Symfony\Component\HttpFoundation\Request;
  15. use Symfony\Component\HttpFoundation\RequestStack;
  16. use Symfony\Component\HttpFoundation\Response;
  17. use Symfony\Component\HttpFoundation\Session\SessionBagInterface;
  18. use Symfony\Component\HttpFoundation\Session\SessionInterface;
  19. use Symfony\Component\HttpKernel\Event\ControllerEvent;
  20. use Symfony\Component\HttpKernel\Event\ResponseEvent;
  21. use Symfony\Component\HttpKernel\KernelEvents;
  22. use Symfony\Component\VarDumper\Cloner\Data;
  23. /**
  24. * @author Fabien Potencier <fabien@symfony.com>
  25. *
  26. * @final
  27. */
  28. class RequestDataCollector extends DataCollector implements EventSubscriberInterface, LateDataCollectorInterface
  29. {
  30. /**
  31. * @var \SplObjectStorage<Request, callable>
  32. */
  33. private \SplObjectStorage $controllers;
  34. private array $sessionUsages = [];
  35. private ?RequestStack $requestStack;
  36. public function __construct(?RequestStack $requestStack = null)
  37. {
  38. $this->controllers = new \SplObjectStorage();
  39. $this->requestStack = $requestStack;
  40. }
  41. public function collect(Request $request, Response $response, ?\Throwable $exception = null): void
  42. {
  43. // attributes are serialized and as they can be anything, they need to be converted to strings.
  44. $attributes = [];
  45. $route = '';
  46. foreach ($request->attributes->all() as $key => $value) {
  47. if ('_route' === $key) {
  48. $route = \is_object($value) ? $value->getPath() : $value;
  49. $attributes[$key] = $route;
  50. } else {
  51. $attributes[$key] = $value;
  52. }
  53. }
  54. $content = $request->getContent();
  55. $sessionMetadata = [];
  56. $sessionAttributes = [];
  57. $flashes = [];
  58. if (!$request->attributes->getBoolean('_stateless') && $request->hasSession()) {
  59. $session = $request->getSession();
  60. if ($session->isStarted()) {
  61. $sessionMetadata['Created'] = date(\DATE_RFC822, $session->getMetadataBag()->getCreated());
  62. $sessionMetadata['Last used'] = date(\DATE_RFC822, $session->getMetadataBag()->getLastUsed());
  63. $sessionMetadata['Lifetime'] = $session->getMetadataBag()->getLifetime();
  64. $sessionAttributes = $session->all();
  65. $flashes = $session->getFlashBag()->peekAll();
  66. }
  67. }
  68. $statusCode = $response->getStatusCode();
  69. $responseCookies = [];
  70. foreach ($response->headers->getCookies() as $cookie) {
  71. $responseCookies[$cookie->getName()] = $cookie;
  72. }
  73. $dotenvVars = [];
  74. foreach (explode(',', $_SERVER['SYMFONY_DOTENV_VARS'] ?? $_ENV['SYMFONY_DOTENV_VARS'] ?? '') as $name) {
  75. if ('' !== $name && isset($_ENV[$name])) {
  76. $dotenvVars[$name] = $_ENV[$name];
  77. }
  78. }
  79. $this->data = [
  80. 'method' => $request->getMethod(),
  81. 'format' => $request->getRequestFormat(),
  82. 'content_type' => $response->headers->get('Content-Type', 'text/html'),
  83. 'status_text' => Response::$statusTexts[$statusCode] ?? '',
  84. 'status_code' => $statusCode,
  85. 'request_query' => $request->query->all(),
  86. 'request_request' => $request->request->all(),
  87. 'request_files' => $request->files->all(),
  88. 'request_headers' => $request->headers->all(),
  89. 'request_server' => $request->server->all(),
  90. 'request_cookies' => $request->cookies->all(),
  91. 'request_attributes' => $attributes,
  92. 'route' => $route,
  93. 'response_headers' => $response->headers->all(),
  94. 'response_cookies' => $responseCookies,
  95. 'session_metadata' => $sessionMetadata,
  96. 'session_attributes' => $sessionAttributes,
  97. 'session_usages' => array_values($this->sessionUsages),
  98. 'stateless_check' => $this->requestStack?->getMainRequest()?->attributes->get('_stateless') ?? false,
  99. 'flashes' => $flashes,
  100. 'path_info' => $request->getPathInfo(),
  101. 'controller' => 'n/a',
  102. 'locale' => $request->getLocale(),
  103. 'dotenv_vars' => $dotenvVars,
  104. ];
  105. if (isset($this->data['request_headers']['php-auth-pw'])) {
  106. $this->data['request_headers']['php-auth-pw'] = '******';
  107. }
  108. if (isset($this->data['request_server']['PHP_AUTH_PW'])) {
  109. $this->data['request_server']['PHP_AUTH_PW'] = '******';
  110. }
  111. if (isset($this->data['request_request']['_password'])) {
  112. $encodedPassword = rawurlencode($this->data['request_request']['_password']);
  113. $content = str_replace('_password='.$encodedPassword, '_password=******', $content);
  114. $this->data['request_request']['_password'] = '******';
  115. }
  116. $this->data['content'] = $content;
  117. foreach ($this->data as $key => $value) {
  118. if (!\is_array($value)) {
  119. continue;
  120. }
  121. if ('request_headers' === $key || 'response_headers' === $key) {
  122. $this->data[$key] = array_map(fn ($v) => isset($v[0]) && !isset($v[1]) ? $v[0] : $v, $value);
  123. }
  124. }
  125. if (isset($this->controllers[$request])) {
  126. $this->data['controller'] = $this->parseController($this->controllers[$request]);
  127. unset($this->controllers[$request]);
  128. }
  129. if ($request->attributes->has('_redirected') && $redirectCookie = $request->cookies->get('sf_redirect')) {
  130. $this->data['redirect'] = json_decode($redirectCookie, true);
  131. $response->headers->clearCookie('sf_redirect');
  132. }
  133. if ($response->isRedirect()) {
  134. $response->headers->setCookie(new Cookie(
  135. 'sf_redirect',
  136. json_encode([
  137. 'token' => $response->headers->get('x-debug-token'),
  138. 'route' => $request->attributes->get('_route', 'n/a'),
  139. 'method' => $request->getMethod(),
  140. 'controller' => $this->parseController($request->attributes->get('_controller')),
  141. 'status_code' => $statusCode,
  142. 'status_text' => Response::$statusTexts[$statusCode],
  143. ]),
  144. 0, '/', null, $request->isSecure(), true, false, 'lax'
  145. ));
  146. }
  147. $this->data['identifier'] = $this->data['route'] ?: (\is_array($this->data['controller']) ? $this->data['controller']['class'].'::'.$this->data['controller']['method'].'()' : $this->data['controller']);
  148. if ($response->headers->has('x-previous-debug-token')) {
  149. $this->data['forward_token'] = $response->headers->get('x-previous-debug-token');
  150. }
  151. }
  152. public function lateCollect(): void
  153. {
  154. $this->data = $this->cloneVar($this->data);
  155. }
  156. public function reset(): void
  157. {
  158. parent::reset();
  159. $this->controllers = new \SplObjectStorage();
  160. $this->sessionUsages = [];
  161. }
  162. public function getMethod(): string
  163. {
  164. return $this->data['method'];
  165. }
  166. public function getPathInfo(): string
  167. {
  168. return $this->data['path_info'];
  169. }
  170. /**
  171. * @return ParameterBag
  172. */
  173. public function getRequestRequest()
  174. {
  175. return new ParameterBag($this->data['request_request']->getValue());
  176. }
  177. /**
  178. * @return ParameterBag
  179. */
  180. public function getRequestQuery()
  181. {
  182. return new ParameterBag($this->data['request_query']->getValue());
  183. }
  184. /**
  185. * @return ParameterBag
  186. */
  187. public function getRequestFiles()
  188. {
  189. return new ParameterBag($this->data['request_files']->getValue());
  190. }
  191. /**
  192. * @return ParameterBag
  193. */
  194. public function getRequestHeaders()
  195. {
  196. return new ParameterBag($this->data['request_headers']->getValue());
  197. }
  198. /**
  199. * @return ParameterBag
  200. */
  201. public function getRequestServer(bool $raw = false)
  202. {
  203. return new ParameterBag($this->data['request_server']->getValue($raw));
  204. }
  205. /**
  206. * @return ParameterBag
  207. */
  208. public function getRequestCookies(bool $raw = false)
  209. {
  210. return new ParameterBag($this->data['request_cookies']->getValue($raw));
  211. }
  212. /**
  213. * @return ParameterBag
  214. */
  215. public function getRequestAttributes()
  216. {
  217. return new ParameterBag($this->data['request_attributes']->getValue());
  218. }
  219. /**
  220. * @return ParameterBag
  221. */
  222. public function getResponseHeaders()
  223. {
  224. return new ParameterBag($this->data['response_headers']->getValue());
  225. }
  226. /**
  227. * @return ParameterBag
  228. */
  229. public function getResponseCookies()
  230. {
  231. return new ParameterBag($this->data['response_cookies']->getValue());
  232. }
  233. public function getSessionMetadata(): array
  234. {
  235. return $this->data['session_metadata']->getValue();
  236. }
  237. public function getSessionAttributes(): array
  238. {
  239. return $this->data['session_attributes']->getValue();
  240. }
  241. public function getStatelessCheck(): bool
  242. {
  243. return $this->data['stateless_check'];
  244. }
  245. public function getSessionUsages(): Data|array
  246. {
  247. return $this->data['session_usages'];
  248. }
  249. public function getFlashes(): array
  250. {
  251. return $this->data['flashes']->getValue();
  252. }
  253. /**
  254. * @return string|resource
  255. */
  256. public function getContent()
  257. {
  258. return $this->data['content'];
  259. }
  260. /**
  261. * @return bool
  262. */
  263. public function isJsonRequest()
  264. {
  265. return 1 === preg_match('{^application/(?:\w+\++)*json$}i', $this->data['request_headers']['content-type']);
  266. }
  267. /**
  268. * @return string|null
  269. */
  270. public function getPrettyJson()
  271. {
  272. $decoded = json_decode($this->getContent());
  273. return \JSON_ERROR_NONE === json_last_error() ? json_encode($decoded, \JSON_PRETTY_PRINT) : null;
  274. }
  275. public function getContentType(): string
  276. {
  277. return $this->data['content_type'];
  278. }
  279. public function getStatusText(): string
  280. {
  281. return $this->data['status_text'];
  282. }
  283. public function getStatusCode(): int
  284. {
  285. return $this->data['status_code'];
  286. }
  287. public function getFormat(): string
  288. {
  289. return $this->data['format'];
  290. }
  291. public function getLocale(): string
  292. {
  293. return $this->data['locale'];
  294. }
  295. /**
  296. * @return ParameterBag
  297. */
  298. public function getDotenvVars()
  299. {
  300. return new ParameterBag($this->data['dotenv_vars']->getValue());
  301. }
  302. /**
  303. * Gets the route name.
  304. *
  305. * The _route request attributes is automatically set by the Router Matcher.
  306. */
  307. public function getRoute(): string
  308. {
  309. return $this->data['route'];
  310. }
  311. public function getIdentifier(): string
  312. {
  313. return $this->data['identifier'];
  314. }
  315. /**
  316. * Gets the route parameters.
  317. *
  318. * The _route_params request attributes is automatically set by the RouterListener.
  319. */
  320. public function getRouteParams(): array
  321. {
  322. return isset($this->data['request_attributes']['_route_params']) ? $this->data['request_attributes']['_route_params']->getValue() : [];
  323. }
  324. /**
  325. * Gets the parsed controller.
  326. *
  327. * @return array|string|Data The controller as a string or array of data
  328. * with keys 'class', 'method', 'file' and 'line'
  329. */
  330. public function getController(): array|string|Data
  331. {
  332. return $this->data['controller'];
  333. }
  334. /**
  335. * Gets the previous request attributes.
  336. *
  337. * @return array|Data|false A legacy array of data from the previous redirection response
  338. * or false otherwise
  339. */
  340. public function getRedirect(): array|Data|false
  341. {
  342. return $this->data['redirect'] ?? false;
  343. }
  344. public function getForwardToken(): ?string
  345. {
  346. return $this->data['forward_token'] ?? null;
  347. }
  348. public function onKernelController(ControllerEvent $event): void
  349. {
  350. $this->controllers[$event->getRequest()] = $event->getController();
  351. }
  352. public function onKernelResponse(ResponseEvent $event): void
  353. {
  354. if (!$event->isMainRequest()) {
  355. return;
  356. }
  357. if ($event->getRequest()->cookies->has('sf_redirect')) {
  358. $event->getRequest()->attributes->set('_redirected', true);
  359. }
  360. }
  361. public static function getSubscribedEvents(): array
  362. {
  363. return [
  364. KernelEvents::CONTROLLER => 'onKernelController',
  365. KernelEvents::RESPONSE => 'onKernelResponse',
  366. ];
  367. }
  368. public function getName(): string
  369. {
  370. return 'request';
  371. }
  372. public function collectSessionUsage(): void
  373. {
  374. $trace = debug_backtrace(\DEBUG_BACKTRACE_IGNORE_ARGS);
  375. $traceEndIndex = \count($trace) - 1;
  376. for ($i = $traceEndIndex; $i > 0; --$i) {
  377. if (null !== ($class = $trace[$i]['class'] ?? null) && (is_subclass_of($class, SessionInterface::class) || is_subclass_of($class, SessionBagInterface::class))) {
  378. $traceEndIndex = $i;
  379. break;
  380. }
  381. }
  382. if ((\count($trace) - 1) === $traceEndIndex) {
  383. return;
  384. }
  385. // Remove part of the backtrace that belongs to session only
  386. array_splice($trace, 0, $traceEndIndex);
  387. // Merge identical backtraces generated by internal call reports
  388. $name = \sprintf('%s:%s', $trace[1]['class'] ?? $trace[0]['file'], $trace[0]['line']);
  389. if (!\array_key_exists($name, $this->sessionUsages)) {
  390. $this->sessionUsages[$name] = [
  391. 'name' => $name,
  392. 'file' => $trace[0]['file'],
  393. 'line' => $trace[0]['line'],
  394. 'trace' => $trace,
  395. ];
  396. }
  397. }
  398. /**
  399. * @return array|string An array of controller data or a simple string
  400. */
  401. private function parseController(array|object|string|null $controller): array|string
  402. {
  403. if (\is_string($controller) && str_contains($controller, '::')) {
  404. $controller = explode('::', $controller);
  405. }
  406. if (\is_array($controller)) {
  407. try {
  408. $r = new \ReflectionMethod($controller[0], $controller[1]);
  409. return [
  410. 'class' => \is_object($controller[0]) ? get_debug_type($controller[0]) : $controller[0],
  411. 'method' => $controller[1],
  412. 'file' => $r->getFileName(),
  413. 'line' => $r->getStartLine(),
  414. ];
  415. } catch (\ReflectionException) {
  416. if (\is_callable($controller)) {
  417. // using __call or __callStatic
  418. return [
  419. 'class' => \is_object($controller[0]) ? get_debug_type($controller[0]) : $controller[0],
  420. 'method' => $controller[1],
  421. 'file' => 'n/a',
  422. 'line' => 'n/a',
  423. ];
  424. }
  425. }
  426. }
  427. if ($controller instanceof \Closure) {
  428. $r = new \ReflectionFunction($controller);
  429. $controller = [
  430. 'class' => $r->getName(),
  431. 'method' => null,
  432. 'file' => $r->getFileName(),
  433. 'line' => $r->getStartLine(),
  434. ];
  435. if (str_contains($r->name, '{closure')) {
  436. return $controller;
  437. }
  438. $controller['method'] = $r->name;
  439. if ($class = \PHP_VERSION_ID >= 80111 ? $r->getClosureCalledClass() : $r->getClosureScopeClass()) {
  440. $controller['class'] = $class->name;
  441. } else {
  442. return $r->name;
  443. }
  444. return $controller;
  445. }
  446. if (\is_object($controller)) {
  447. $r = new \ReflectionClass($controller);
  448. return [
  449. 'class' => $r->getName(),
  450. 'method' => null,
  451. 'file' => $r->getFileName(),
  452. 'line' => $r->getStartLine(),
  453. ];
  454. }
  455. return \is_string($controller) ? $controller : 'n/a';
  456. }
  457. }