modernize oauth token handling
This commit is contained in:
11 files changed
+600
-191
No files matched your search
@@ -0,0 +1,182 @@
|
||||
<?php namespace RVR\PersistentData\Model;
|
||||
|
||||
use DateTime;
|
||||
use SokoWeb\PersistentData\Model\Model;
|
||||
|
||||
class OAuthSession extends Model
|
||||
{
|
||||
protected static string $table = 'oauth_sessions';
|
||||
|
||||
protected static array $fields = ['client_id', 'scope', 'nonce', 'code_challenge', 'code_challenge_method', 'user_id', 'code', 'created', 'expires', 'token_claimed'];
|
||||
|
||||
protected static array $relations = ['user' => User::class];
|
||||
|
||||
private static array $possibleScopeValues = ['openid', 'email', 'profile', 'union_profile'];
|
||||
|
||||
private static array $possibleCodeChallengeMethodValues = ['plain', 'S256'];
|
||||
|
||||
private string $clientId = '';
|
||||
|
||||
private array $scope = [];
|
||||
|
||||
private string $nonce = '';
|
||||
|
||||
private ?string $codeChallenge = null;
|
||||
|
||||
private ?string $codeChallengeMethod = null;
|
||||
|
||||
private ?User $user = null;
|
||||
|
||||
private ?int $userId = null;
|
||||
|
||||
private string $code = '';
|
||||
|
||||
private DateTime $created;
|
||||
|
||||
private DateTime $expires;
|
||||
|
||||
private bool $tokenClaimed = false;
|
||||
|
||||
public function setScopeArray(array $scope): void
|
||||
{
|
||||
$this->scope = array_intersect($scope, self::$possibleScopeValues);
|
||||
}
|
||||
|
||||
public function setClientId(string $clientId): void
|
||||
{
|
||||
$this->clientId = $clientId;
|
||||
}
|
||||
|
||||
public function setScope(string $scope): void
|
||||
{
|
||||
$this->setScopeArray(explode(' ', $scope));
|
||||
}
|
||||
|
||||
public function setNonce(string $nonce): void
|
||||
{
|
||||
$this->nonce = $nonce;
|
||||
}
|
||||
|
||||
public function setCodeChallenge(?string $codeChallenge): void
|
||||
{
|
||||
$this->codeChallenge = $codeChallenge;
|
||||
}
|
||||
|
||||
public function setCodeChallengeMethod(?string $codeChallengeMethod): void
|
||||
{
|
||||
if ($codeChallengeMethod !== null && !in_array($codeChallengeMethod, self::$possibleCodeChallengeMethodValues)) {
|
||||
throw new \UnexpectedValueException($codeChallengeMethod . ' is not possible for challengeMethod!');
|
||||
}
|
||||
$this->codeChallengeMethod = $codeChallengeMethod;
|
||||
}
|
||||
|
||||
public function setUser(User $user): void
|
||||
{
|
||||
$this->user = $user;
|
||||
}
|
||||
|
||||
public function setUserId(int $userId): void
|
||||
{
|
||||
$this->userId = $userId;
|
||||
}
|
||||
|
||||
public function setCode(string $code): void
|
||||
{
|
||||
$this->code = $code;
|
||||
}
|
||||
|
||||
public function setCreatedDate(DateTime $created): void
|
||||
{
|
||||
$this->created = $created;
|
||||
}
|
||||
|
||||
public function setExpiresDate(DateTime $expires): void
|
||||
{
|
||||
$this->expires = $expires;
|
||||
}
|
||||
|
||||
public function setCreated(string $created): void
|
||||
{
|
||||
$this->created = new DateTime($created);
|
||||
}
|
||||
|
||||
public function setExpires(string $expires): void
|
||||
{
|
||||
$this->expires = new DateTime($expires);
|
||||
}
|
||||
|
||||
public function setTokenClaimed(bool $tokenClaimed): void
|
||||
{
|
||||
$this->tokenClaimed = $tokenClaimed;
|
||||
}
|
||||
|
||||
public function getClientId(): string
|
||||
{
|
||||
return $this->clientId;
|
||||
}
|
||||
|
||||
public function getScope(): string
|
||||
{
|
||||
return implode(' ', $this->scope);
|
||||
}
|
||||
|
||||
public function getScopeArray(): array
|
||||
{
|
||||
return $this->scope;
|
||||
}
|
||||
|
||||
public function getNonce(): string
|
||||
{
|
||||
return $this->nonce;
|
||||
}
|
||||
|
||||
public function getCodeChallenge(): ?string
|
||||
{
|
||||
return $this->codeChallenge;
|
||||
}
|
||||
|
||||
public function getCodeChallengeMethod(): ?string
|
||||
{
|
||||
return $this->codeChallengeMethod;
|
||||
}
|
||||
|
||||
public function getUser(): ?User
|
||||
{
|
||||
return $this->user;
|
||||
}
|
||||
|
||||
public function getUserId(): ?int
|
||||
{
|
||||
return $this->userId;
|
||||
}
|
||||
|
||||
public function getCode(): string
|
||||
{
|
||||
return $this->code;
|
||||
}
|
||||
|
||||
public function getCreatedDate(): DateTime
|
||||
{
|
||||
return $this->created;
|
||||
}
|
||||
|
||||
public function getCreated(): string
|
||||
{
|
||||
return $this->created->format('Y-m-d H:i:s');
|
||||
}
|
||||
|
||||
public function getExpiresDate(): DateTime
|
||||
{
|
||||
return $this->expires;
|
||||
}
|
||||
|
||||
public function getExpires(): string
|
||||
{
|
||||
return $this->expires->format('Y-m-d H:i:s');
|
||||
}
|
||||
|
||||
public function getTokenClaimed(): bool
|
||||
{
|
||||
return $this->tokenClaimed;
|
||||
}
|
||||
}
|
||||
@@ -7,61 +7,26 @@ class OAuthToken extends Model
|
||||
{
|
||||
protected static string $table = 'oauth_tokens';
|
||||
|
||||
protected static array $fields = ['scope', 'nonce', 'user_id', 'code', 'access_token', 'created', 'expires'];
|
||||
protected static array $fields = ['session_id', 'created', 'expires'];
|
||||
|
||||
protected static array $relations = ['user' => User::class];
|
||||
protected static array $relations = ['session' => OAuthSession::class];
|
||||
|
||||
private static array $possibleScopeValues = ['openid', 'email', 'profile'];
|
||||
private ?OAuthSession $session = null;
|
||||
|
||||
private array $scope = [];
|
||||
|
||||
private string $nonce = '';
|
||||
|
||||
private ?User $user = null;
|
||||
|
||||
private ?int $userId = null;
|
||||
|
||||
private string $code = '';
|
||||
|
||||
private string $accessToken = '';
|
||||
private ?int $sessionId = null;
|
||||
|
||||
private DateTime $created;
|
||||
|
||||
private DateTime $expires;
|
||||
|
||||
public function setScopeArray(array $scope): void
|
||||
public function setSession(OAuthSession $session): void
|
||||
{
|
||||
$this->scope = array_intersect($scope, self::$possibleScopeValues);
|
||||
$this->session = $session;
|
||||
}
|
||||
|
||||
public function setScope(string $scope): void
|
||||
public function setSessionId(int $sessionId): void
|
||||
{
|
||||
$this->setScopeArray(explode(' ', $scope));
|
||||
}
|
||||
|
||||
public function setNonce(string $nonce): void
|
||||
{
|
||||
$this->nonce = $nonce;
|
||||
}
|
||||
|
||||
public function setUser(User $user): void
|
||||
{
|
||||
$this->user = $user;
|
||||
}
|
||||
|
||||
public function setUserId(int $userId): void
|
||||
{
|
||||
$this->userId = $userId;
|
||||
}
|
||||
|
||||
public function setCode(string $code): void
|
||||
{
|
||||
$this->code = $code;
|
||||
}
|
||||
|
||||
public function setAccessToken(string $accessToken): void
|
||||
{
|
||||
$this->accessToken = $accessToken;
|
||||
$this->sessionId = $sessionId;
|
||||
}
|
||||
|
||||
public function setCreatedDate(DateTime $created): void
|
||||
@@ -84,39 +49,14 @@ class OAuthToken extends Model
|
||||
$this->expires = new DateTime($expires);
|
||||
}
|
||||
|
||||
public function getScope(): string
|
||||
public function getSession(): ?OAuthSession
|
||||
{
|
||||
return implode(' ', $this->scope);
|
||||
return $this->session;
|
||||
}
|
||||
|
||||
public function getScopeArray(): array
|
||||
public function getSessionId(): ?int
|
||||
{
|
||||
return $this->scope;
|
||||
}
|
||||
|
||||
public function getNonce(): string
|
||||
{
|
||||
return $this->nonce;
|
||||
}
|
||||
|
||||
public function getUser(): ?User
|
||||
{
|
||||
return $this->user;
|
||||
}
|
||||
|
||||
public function getUserId(): ?int
|
||||
{
|
||||
return $this->userId;
|
||||
}
|
||||
|
||||
public function getCode(): string
|
||||
{
|
||||
return $this->code;
|
||||
}
|
||||
|
||||
public function getAccessToken(): string
|
||||
{
|
||||
return $this->accessToken;
|
||||
return $this->sessionId;
|
||||
}
|
||||
|
||||
public function getCreatedDate(): DateTime
|
||||
|
||||
Reference in new issue
Block a user