MAPG-142 redefine tokens and increase OAuth security with nonce

This commit is contained in:
bence committed 2020-07-05 14:24:05 +02:00
1 parent 7e3315fc88
commit ab23b37b97
10 files changed
+63 -32

No files matched your search

+9 -2
View File
@@ -59,14 +59,17 @@ class UserController implements ISecured
$user = $this->request->user();
$state = bin2hex(random_bytes(16));
$nonce = bin2hex(random_bytes(16));
$this->request->session()->set('oauth_state', $state);
$this->request->session()->set('oauth_nonce', $nonce);
$oAuth = new GoogleOAuth(new Request());
$url = $oAuth->getDialogUrl(
$state,
$this->request->getBase() . '/' . \Container::$routeCollection->getRoute('account.googleAuthenticate-action')->generateLink(),
$nonce,
$user->getEmail()
);
@@ -95,9 +98,13 @@ class UserController implements ISecured
}
$jwtParser = new JwtParser($tokenData['id_token']);
$userData = $jwtParser->getPayload();
$idToken = $jwtParser->getPayload();
if ($userData['sub'] !== $user->getGoogleSub()) {
if ($idToken['nonce'] !== $this->request->session()->get('oauth_nonce')) {
return new HtmlContent('account/google_authenticate', ['success' => false]);
}
if ($idToken['sub'] !== $user->getGoogleSub()) {
return new HtmlContent('account/google_authenticate', [
'success' => false,
'errorText' => 'This Google account is not linked to your account.'