This commit is contained in:
9 files changed
+338
-8
No files matched your search
@@ -3,6 +3,7 @@
|
||||
use DateTime;
|
||||
use RVR\PersistentData\Model\OAuthToken;
|
||||
use RVR\PersistentData\Model\User;
|
||||
use RVR\Repository\OAuthClientRepository;
|
||||
use SokoWeb\Interfaces\Authorization\ISecured;
|
||||
use SokoWeb\Interfaces\Request\IRequest;
|
||||
use SokoWeb\Interfaces\Response\IRedirect;
|
||||
@@ -16,10 +17,13 @@ class OAuthAuthController implements ISecured
|
||||
|
||||
private PersistentDataManager $pdm;
|
||||
|
||||
private OAuthClientRepository $oAuthClientRepository;
|
||||
|
||||
public function __construct(IRequest $request)
|
||||
{
|
||||
$this->request = $request;
|
||||
$this->pdm = new PersistentDataManager();
|
||||
$this->oAuthClientRepository = new OAuthClientRepository();
|
||||
}
|
||||
|
||||
public function authorize(): bool
|
||||
@@ -30,15 +34,30 @@ class OAuthAuthController implements ISecured
|
||||
public function auth()
|
||||
{
|
||||
$redirectUri = $this->request->query('redirect_uri');
|
||||
$clientId = $this->request->query('client_id');
|
||||
$scope = $this->request->query('scope') ? $this->request->query('scope'): '';
|
||||
$state = $this->request->query('state');
|
||||
$nonce = $this->request->query('nonce') ? $this->request->query('nonce'): '';
|
||||
|
||||
if (!$redirectUri || !$state) {
|
||||
if (!$clientId || !$redirectUri || !$state) {
|
||||
return new HtmlContent('oauth/oauth_error', ['error' => 'An invalid request was made. Please start authentication again.']);
|
||||
}
|
||||
|
||||
$this->request->session()->delete('oauth_payload');
|
||||
$client = $this->oAuthClientRepository->getByClientId($clientId);
|
||||
if ($client === null) {
|
||||
return new HtmlContent('oauth/oauth_error', ['error' => 'Client is not authorized.']);
|
||||
}
|
||||
|
||||
$redirectUriParsed = parse_url($redirectUri);
|
||||
$redirectUriBase = $redirectUriParsed['scheme'] . '://' . $redirectUriParsed['host'] . $redirectUriParsed['path'];
|
||||
$redirectUriQuery = [];
|
||||
if (isset($redirectUriParsed['query'])) {
|
||||
parse_str($redirectUriParsed['query'], $redirectUriQuery);
|
||||
}
|
||||
|
||||
if (!in_array($redirectUriBase, $client->getRedirectUrisArray())) {
|
||||
return new HtmlContent('oauth/oauth_error', ['error' => 'Redirect URI \'' . $redirectUriBase .'\' is not allowed for this client.']);
|
||||
}
|
||||
|
||||
/**
|
||||
* @var ?User $user
|
||||
@@ -57,13 +76,11 @@ class OAuthAuthController implements ISecured
|
||||
$token->setExpiresDate(new DateTime('+5 minutes'));
|
||||
$this->pdm->saveToDb($token);
|
||||
|
||||
$redirectUri = $redirectUri;
|
||||
$additionalUriParams = [
|
||||
$redirectUriQuery = array_merge($redirectUriQuery, [
|
||||
'state' => $state,
|
||||
'code' => $code
|
||||
];
|
||||
$and = (strpos($redirectUri, '?') !== false) ? '&' : '?';
|
||||
$finalRedirectUri = $redirectUri . $and . http_build_query($additionalUriParams);
|
||||
]);
|
||||
$finalRedirectUri = $redirectUriBase . '?' . http_build_query($redirectUriQuery);
|
||||
|
||||
return new Redirect($finalRedirectUri, IRedirect::TEMPORARY);
|
||||
}
|
||||
|
||||
@@ -5,6 +5,7 @@ use Firebase\JWT\JWT;
|
||||
use RVR\Repository\OAuthTokenRepository;
|
||||
use RVR\Repository\UserRepository;
|
||||
use RVR\PersistentData\Model\User;
|
||||
use RVR\Repository\OAuthClientRepository;
|
||||
use SokoWeb\Interfaces\Request\IRequest;
|
||||
use SokoWeb\Interfaces\Response\IContent;
|
||||
use SokoWeb\Response\JsonContent;
|
||||
@@ -13,6 +14,8 @@ class OAuthController
|
||||
{
|
||||
private IRequest $request;
|
||||
|
||||
private OAuthClientRepository $oAuthClientRepository;
|
||||
|
||||
private OAuthTokenRepository $oAuthTokenRepository;
|
||||
|
||||
private UserRepository $userRepository;
|
||||
@@ -20,14 +23,31 @@ class OAuthController
|
||||
public function __construct(IRequest $request)
|
||||
{
|
||||
$this->request = $request;
|
||||
$this->oAuthClientRepository = new OAuthClientRepository();
|
||||
$this->oAuthTokenRepository = new OAuthTokenRepository();
|
||||
$this->userRepository = new UserRepository();
|
||||
}
|
||||
|
||||
public function getToken(): ?IContent
|
||||
{
|
||||
$token = $this->oAuthTokenRepository->getByCode($this->request->post('code'));
|
||||
$clientId = $this->request->post('client_id');
|
||||
$clientSecret = $this->request->post('client_secret');
|
||||
$code = $this->request->post('code');
|
||||
|
||||
if (!$clientId || !$clientSecret || !$code) {
|
||||
return new JsonContent([
|
||||
'error' => 'An invalid request was made.'
|
||||
]);
|
||||
}
|
||||
|
||||
$client = $this->oAuthClientRepository->getByClientId($clientId);
|
||||
if ($client === null || $client->getClientSecret() !== $clientSecret) {
|
||||
return new JsonContent([
|
||||
'error' => 'Client is not authorized.'
|
||||
]);
|
||||
}
|
||||
|
||||
$token = $this->oAuthTokenRepository->getByCode($code);
|
||||
if ($token === null || $token->getExpiresDate() < new DateTime()) {
|
||||
return new JsonContent([
|
||||
'error' => 'The provided code is invalid.'
|
||||
|
||||
Reference in new issue
Block a user