Compare commits

...
Author SHA1 Message Date
bence c9a06e5ada Merge pull request 'add aud to jwt' (!15) from feature/add-oauth-audience into master
rvr-nextgen/pipeline/head This commit looks good
Reviewed-on: #15
2023-04-12 00:44:52 +02:00
bence 4f007765f4 Merge pull request 'omit whitespace in main layout' (!14) from bugfix/layout-fix into master
rvr-nextgen/pipeline/head This commit looks good
Reviewed-on: #14
2023-04-12 00:42:40 +02:00
bence 97780eb079 add aud to jwt
rvr-nextgen/pipeline/pr-master This commit looks good
2023-04-12 00:41:20 +02:00
bence ed137b38de omit whitespace in main layout
rvr-nextgen/pipeline/pr-master This commit looks good
2023-04-09 03:16:45 +02:00
5 changed files with 21 additions and 4 deletions

No files matched your search

@@ -0,0 +1,2 @@
ALTER TABLE `oauth_tokens`
ADD `audience` varchar(255) NOT NULL DEFAULT '';
+3 -1
View File
@@ -49,7 +49,8 @@ class OAuthAuthController implements ISecured
}
$redirectUriParsed = parse_url($redirectUri);
$redirectUriBase = $redirectUriParsed['scheme'] . '://' . $redirectUriParsed['host'] . $redirectUriParsed['path'];
$redirectUriHost = $redirectUriParsed['scheme'] . '://' . $redirectUriParsed['host'];
$redirectUriBase = $redirectUriHost . $redirectUriParsed['path'];
$redirectUriQuery = [];
if (isset($redirectUriParsed['query'])) {
parse_str($redirectUriParsed['query'], $redirectUriQuery);
@@ -72,6 +73,7 @@ class OAuthAuthController implements ISecured
$token->setUser($user);
$token->setCode($code);
$token->setAccessToken($accessToken);
$token->setAudience($redirectUriHost);
$token->setCreatedDate(new DateTime());
$token->setExpiresDate(new DateTime('+5 minutes'));
$this->pdm->saveToDb($token);
+1
View File
@@ -59,6 +59,7 @@ class OAuthController
'iat' => (int)$token->getCreatedDate()->getTimestamp(),
'nbf' => (int)$token->getCreatedDate()->getTimestamp(),
'exp' => (int)$token->getExpiresDate()->getTimestamp(),
'aud' => $token->getAudience(),
'nonce' => $token->getNonce()
], $this->getUserInfoInternal(
$this->userRepository->getById($token->getUserId()),
+13 -1
View File
@@ -7,7 +7,7 @@ class OAuthToken extends Model
{
protected static string $table = 'oauth_tokens';
protected static array $fields = ['scope', 'nonce', 'user_id', 'code', 'access_token', 'created', 'expires'];
protected static array $fields = ['scope', 'nonce', 'user_id', 'code', 'access_token', 'audience', 'created', 'expires'];
protected static array $relations = ['user' => User::class];
@@ -25,6 +25,8 @@ class OAuthToken extends Model
private string $accessToken = '';
private string $audience = '';
private DateTime $created;
private DateTime $expires;
@@ -64,6 +66,11 @@ class OAuthToken extends Model
$this->accessToken = $accessToken;
}
public function setAudience(string $audience): void
{
$this->audience = $audience;
}
public function setCreatedDate(DateTime $created): void
{
$this->created = $created;
@@ -119,6 +126,11 @@ class OAuthToken extends Model
return $this->accessToken;
}
public function getAudience(): string
{
return $this->audience;
}
public function getCreatedDate(): DateTime
{
return $this->created;
+2 -2
View File
@@ -25,8 +25,8 @@
@yields('main')
</main>
<footer>
<p><?= round($__debug_runtime, 0) ?> ms</p>
<p><span class="bold"><?= $_ENV['APP_NAME'] ?></span> <?= str_replace('Release_', '', VERSION) ?></p><!--
<p><?= round($__debug_runtime, 0) ?> ms</p><!--
--><p><span class="bold"><?= $_ENV['APP_NAME'] ?></span> <?= str_replace('Release_', '', VERSION) ?></p><!--
--><p>&copy; The RVR Contributors <?= (new DateTime(REVISION_DATE))->format('Y') ?></p>
</footer>
@endsection