This commit is contained in:
9 files changed
+338
-8
No files matched your search
@@ -5,6 +5,7 @@ use Firebase\JWT\JWT;
|
||||
use RVR\Repository\OAuthTokenRepository;
|
||||
use RVR\Repository\UserRepository;
|
||||
use RVR\PersistentData\Model\User;
|
||||
use RVR\Repository\OAuthClientRepository;
|
||||
use SokoWeb\Interfaces\Request\IRequest;
|
||||
use SokoWeb\Interfaces\Response\IContent;
|
||||
use SokoWeb\Response\JsonContent;
|
||||
@@ -13,6 +14,8 @@ class OAuthController
|
||||
{
|
||||
private IRequest $request;
|
||||
|
||||
private OAuthClientRepository $oAuthClientRepository;
|
||||
|
||||
private OAuthTokenRepository $oAuthTokenRepository;
|
||||
|
||||
private UserRepository $userRepository;
|
||||
@@ -20,14 +23,31 @@ class OAuthController
|
||||
public function __construct(IRequest $request)
|
||||
{
|
||||
$this->request = $request;
|
||||
$this->oAuthClientRepository = new OAuthClientRepository();
|
||||
$this->oAuthTokenRepository = new OAuthTokenRepository();
|
||||
$this->userRepository = new UserRepository();
|
||||
}
|
||||
|
||||
public function getToken(): ?IContent
|
||||
{
|
||||
$token = $this->oAuthTokenRepository->getByCode($this->request->post('code'));
|
||||
$clientId = $this->request->post('client_id');
|
||||
$clientSecret = $this->request->post('client_secret');
|
||||
$code = $this->request->post('code');
|
||||
|
||||
if (!$clientId || !$clientSecret || !$code) {
|
||||
return new JsonContent([
|
||||
'error' => 'An invalid request was made.'
|
||||
]);
|
||||
}
|
||||
|
||||
$client = $this->oAuthClientRepository->getByClientId($clientId);
|
||||
if ($client === null || $client->getClientSecret() !== $clientSecret) {
|
||||
return new JsonContent([
|
||||
'error' => 'Client is not authorized.'
|
||||
]);
|
||||
}
|
||||
|
||||
$token = $this->oAuthTokenRepository->getByCode($code);
|
||||
if ($token === null || $token->getExpiresDate() < new DateTime()) {
|
||||
return new JsonContent([
|
||||
'error' => 'The provided code is invalid.'
|
||||
|
||||
Reference in new issue
Block a user