Compare commits

..
Author SHA1 Message Date
bence 366abf61b3 Merge pull request 'use name 'oauth_payload' for data received from oauth authentication request' (!10) from bugfix/fix-conflicting-session-keys into master
rvr-nextgen/pipeline/head This commit looks good
Reviewed-on: #10
2023-04-08 21:25:57 +02:00
bence 367e78cbf8 use name 'oauth_payload' for data received from oauth authentication request
rvr-nextgen/pipeline/pr-master This commit looks good
2023-04-08 21:21:30 +02:00
bence c056e0bdfc Merge pull request 'fix redirect again - hopefully last time' (!9) from bugfix/fix-redirects-again into master
rvr-nextgen/pipeline/head This commit looks good
Reviewed-on: #9
2023-04-08 21:11:31 +02:00
bence 12890293e0 fix redirect again - hopefully last time
rvr-nextgen/pipeline/pr-master This commit looks good
2023-04-08 20:54:18 +02:00
3 changed files with 12 additions and 12 deletions

No files matched your search

+1 -1
View File
@@ -29,7 +29,7 @@ if ($match !== null) {
} }
if (!$authorized) { if (!$authorized) {
Container::$request->session()->set('redirect_after_login', '/' . $url); Container::$request->session()->set('redirect_after_login', $url);
$response = new Redirect(Container::$routeCollection->getRoute('login')->generateLink(), IRedirect::TEMPORARY); $response = new Redirect(Container::$routeCollection->getRoute('login')->generateLink(), IRedirect::TEMPORARY);
header('Location: ' . $response->getUrl(), true, $response->getHttpCode()); header('Location: ' . $response->getUrl(), true, $response->getHttpCode());
return; return;
+4 -4
View File
@@ -47,7 +47,7 @@ class LoginController
return new Redirect($this->redirectUrl, IRedirect::TEMPORARY); return new Redirect($this->redirectUrl, IRedirect::TEMPORARY);
} }
return new HtmlContent('login/login', ['redirectUrl' => $this->redirectUrl]); return new HtmlContent('login/login', ['redirectUrl' => '/' . $this->redirectUrl]);
} }
public function getGoogleLoginRedirect(): IRedirect public function getGoogleLoginRedirect(): IRedirect
@@ -99,7 +99,7 @@ class LoginController
$user = $this->userRepository->getById($resetter->getUserId()); $user = $this->userRepository->getById($resetter->getUserId());
return new HtmlContent('login/reset_password', ['success' => true, 'token' => $token, 'email' => $user->getEmail(), 'redirectUrl' => $this->redirectUrl]); return new HtmlContent('login/reset_password', ['success' => true, 'token' => $token, 'email' => $user->getEmail(), 'redirectUrl' => '/' . $this->redirectUrl]);
} }
public function login(): IContent public function login(): IContent
@@ -183,7 +183,7 @@ class LoginController
$this->deleteRedirectUrl(); $this->deleteRedirectUrl();
return new JsonContent([ return new JsonContent([
'redirect' => [ 'redirect' => [
'target' => $this->redirectUrl 'target' => '/' . $this->redirectUrl
] ]
]); ]);
} }
@@ -247,7 +247,7 @@ class LoginController
$this->deleteRedirectUrl(); $this->deleteRedirectUrl();
return new JsonContent([ return new JsonContent([
'redirect' => [ 'redirect' => [
'target' => $this->redirectUrl 'target' => '/' . $this->redirectUrl
] ]
]); ]);
} }
+7 -7
View File
@@ -36,7 +36,7 @@ class OAuthLoginController
return new HtmlContent('oauth/oauth_error', ['error' => 'An invalid request was made. Please start authentication again.']); return new HtmlContent('oauth/oauth_error', ['error' => 'An invalid request was made. Please start authentication again.']);
} }
$this->request->session()->set('oauth_state', [ $this->request->session()->set('oauth_payload', [
'redirect_uri' => $redirectUri, 'redirect_uri' => $redirectUri,
'state' => $state, 'state' => $state,
'nonce' => $nonce === null ? '' : $nonce 'nonce' => $nonce === null ? '' : $nonce
@@ -49,12 +49,12 @@ class OAuthLoginController
public function finishOauth() public function finishOauth()
{ {
$oauthState = $this->request->session()->get('oauth_state'); $oAuthPayload = $this->request->session()->get('oauth_payload');
if ($oauthState === null) { if ($oAuthPayload === null) {
return new HtmlContent('oauth/oauth_error', ['error' => 'An invalid request was made. Please start authentication again.']); return new HtmlContent('oauth/oauth_error', ['error' => 'An invalid request was made. Please start authentication again.']);
} }
$this->request->session()->delete('oauth_state'); $this->request->session()->delete('oauth_payload');
/** /**
* @var ?User $user * @var ?User $user
@@ -67,16 +67,16 @@ class OAuthLoginController
$code = bin2hex(random_bytes(16)); $code = bin2hex(random_bytes(16));
$token = new OAuthToken(); $token = new OAuthToken();
$token->setNonce($oauthState['nonce']); $token->setNonce($oAuthPayload['nonce']);
$token->setUser($user); $token->setUser($user);
$token->setCode($code); $token->setCode($code);
$token->setCreatedDate(new DateTime()); $token->setCreatedDate(new DateTime());
$token->setExpiresDate(new DateTime('+5 minutes')); $token->setExpiresDate(new DateTime('+5 minutes'));
$this->pdm->saveToDb($token); $this->pdm->saveToDb($token);
$redirectUri = $oauthState['redirect_uri']; $redirectUri = $oAuthPayload['redirect_uri'];
$additionalUriParams = [ $additionalUriParams = [
'state' => $oauthState['state'], 'state' => $oAuthPayload['state'],
'code' => $code 'code' => $code
]; ];
$and = (strpos($redirectUri, '?') !== false) ? '&' : '?'; $and = (strpos($redirectUri, '?') !== false) ? '&' : '?';