Version 5.0.0 beta 1
This commit is contained in:
1 parent
25ddeb65d6
commit
15c7beabc5
6736 files changed
+627902
-497943
No files matched your search
+174
-140
@@ -12,46 +12,73 @@
|
||||
namespace IPS\Api;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
|
||||
use DomainException;
|
||||
use IPS\Db;
|
||||
use IPS\Helpers\Form;
|
||||
use IPS\Helpers\Form\CheckboxSet;
|
||||
use IPS\Helpers\Form\Custom;
|
||||
use IPS\Helpers\Form\Interval;
|
||||
use IPS\Helpers\Form\Matrix;
|
||||
use IPS\Helpers\Form\Radio;
|
||||
use IPS\Helpers\Form\Stack;
|
||||
use IPS\Helpers\Form\Translatable;
|
||||
use IPS\Helpers\Form\Url as FormUrl;
|
||||
use IPS\Helpers\Form\YesNo;
|
||||
use IPS\Http\Url;
|
||||
use IPS\Lang;
|
||||
use IPS\Login;
|
||||
use IPS\Member;
|
||||
use IPS\Member\Device;
|
||||
use IPS\Node\Model;
|
||||
use IPS\Request;
|
||||
use IPS\Settings;
|
||||
use IPS\Theme;
|
||||
use UnderflowException;
|
||||
use function count;
|
||||
use function defined;
|
||||
use function in_array;
|
||||
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* OAuth Client
|
||||
*/
|
||||
class _OAuthClient extends \IPS\Node\Model
|
||||
class OAuthClient extends Model
|
||||
{
|
||||
/**
|
||||
* @brief [ActiveRecord] Multiton Store
|
||||
*/
|
||||
protected static $multitons;
|
||||
protected static array $multitons;
|
||||
|
||||
/**
|
||||
* @brief [ActiveRecord] Database Table
|
||||
*/
|
||||
public static $databaseTable = 'core_oauth_clients';
|
||||
public static ?string $databaseTable = 'core_oauth_clients';
|
||||
|
||||
/**
|
||||
* @brief Database Prefix
|
||||
*/
|
||||
public static $databasePrefix = 'oauth_';
|
||||
public static string $databasePrefix = 'oauth_';
|
||||
|
||||
/**
|
||||
* @brief [ActiveRecord] ID Database Column
|
||||
*/
|
||||
public static $databaseColumnId = 'client_id';
|
||||
public static string $databaseColumnId = 'client_id';
|
||||
|
||||
/**
|
||||
* @brief [Node] Enabled/Disabled Column
|
||||
*/
|
||||
public static $databaseColumnEnabledDisabled = 'enabled';
|
||||
public static ?string $databaseColumnEnabledDisabled = 'enabled';
|
||||
|
||||
/**
|
||||
* @brief [Node] Node Title
|
||||
*/
|
||||
public static $nodeTitle = 'oauth_clients';
|
||||
public static string $nodeTitle = 'oauth_clients';
|
||||
|
||||
/**
|
||||
* @brief [Node] ACP Restrictions
|
||||
@@ -69,7 +96,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
'prefix' => 'foo_', // [Optional] Rather than specifying each key in the map, you can specify a prefix, and it will automatically look for restrictions with the key "[prefix]_add/edit/permissions/delete"
|
||||
* @endcode
|
||||
*/
|
||||
protected static $restrictions = array(
|
||||
protected static ?array $restrictions = array(
|
||||
'app' => 'core',
|
||||
'module' => 'applications',
|
||||
'prefix' => 'oauth_',
|
||||
@@ -78,14 +105,14 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
/**
|
||||
* @brief [Node] Title prefix. If specified, will look for a language key with "{$key}_title" as the key
|
||||
*/
|
||||
public static $titleLangPrefix = 'core_oauth_client_';
|
||||
public static ?string $titleLangPrefix = 'core_oauth_client_';
|
||||
|
||||
/**
|
||||
* Set Default Values (overriding $defaultValues)
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
protected function setDefaultValues()
|
||||
protected function setDefaultValues() : void
|
||||
{
|
||||
$this->access_token_length = 168;
|
||||
$this->prompt = 'reauthorize';
|
||||
@@ -97,10 +124,10 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
/**
|
||||
* [Node] Add/Edit Form
|
||||
*
|
||||
* @param \IPS\Helpers\Form $form The form
|
||||
* @param Form $form The form
|
||||
* @return void
|
||||
*/
|
||||
public function form( &$form )
|
||||
public function form( Form &$form ) : void
|
||||
{
|
||||
$form->id = 'oauth';
|
||||
|
||||
@@ -119,9 +146,9 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
|
||||
$form->addTab('oauth_basic_settings');
|
||||
$form->addHeader('oauth_basic_settings');
|
||||
$form->add( new \IPS\Helpers\Form\Translatable( 'oauth_client_name', NULL, TRUE, array( 'app' => 'core', 'key' => ( $this->client_id ? "core_oauth_client_{$this->client_id}" : NULL ) ) ) );
|
||||
$form->add( new Translatable( 'oauth_client_name', NULL, TRUE, array( 'app' => 'core', 'key' => ( $this->client_id ? "core_oauth_client_{$this->client_id}" : NULL ) ) ) );
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_client_type', $type, TRUE, array(
|
||||
$form->add( new Radio( 'oauth_client_type', $type, TRUE, array(
|
||||
'options' => array(
|
||||
'invision' => 'client_type_invision',
|
||||
'wordpress' => 'client_type_wordpress',
|
||||
@@ -136,7 +163,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
)
|
||||
) ) );
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_api_access', $this->api_access ? $this->api_access : 'rest', TRUE, array(
|
||||
$form->add( new Radio( 'oauth_api_access', $this->api_access ? $this->api_access : 'rest', TRUE, array(
|
||||
'options' => array(
|
||||
'rest' => 'oauth_api_type_rest',
|
||||
'graphql' => 'oauth_api_type_graphql',
|
||||
@@ -149,13 +176,13 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
)
|
||||
), NULL, NULL, NULL, 'oauth_api_access' ) );
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_invision_grant_type', $this->client_id ? $this->grant_types : 'authorization_code', NULL, array(
|
||||
$form->add( new Radio( 'oauth_invision_grant_type', $this->client_id ? $this->grant_types : 'authorization_code', NULL, array(
|
||||
'options' => array(
|
||||
'authorization_code' => 'invision_grant_type_server_authorization_code',
|
||||
'password' => 'invision_grant_type_server_password',
|
||||
),
|
||||
), NULL, NULL, NULL, 'oauth_grant_types_invision' ) );
|
||||
$confidentialGrant = new \IPS\Helpers\Form\CheckboxSet( 'oauth_grant_types_confidential', $this->client_id ? explode( ',', $this->grant_types ) : array( 'authorization_code' ), NULL, array(
|
||||
$confidentialGrant = new CheckboxSet( 'oauth_grant_types_confidential', $this->client_id ? explode( ',', $this->grant_types ) : array( 'authorization_code' ), NULL, array(
|
||||
'options' => array(
|
||||
'authorization_code' => 'grant_type_authorization_code',
|
||||
'implicit' => 'grant_type_implicit',
|
||||
@@ -166,13 +193,13 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
'authorization_code' => array( 'oauth_pkce', 'oauth_use_refresh_tokens' )
|
||||
)
|
||||
), function( $val ) {
|
||||
if ( !$val and \IPS\Request::i()->oauth_client_type === 'confidential' ) {
|
||||
throw new \DomainException('form_required');
|
||||
if ( !$val and Request::i()->oauth_client_type === 'confidential' ) {
|
||||
throw new DomainException('form_required');
|
||||
}
|
||||
}, NULL, NULL, 'oauth_grant_types_confidential' );
|
||||
$confidentialGrant->label = \IPS\Member::loggedIn()->language()->addToStack('oauth_grant_types');
|
||||
$confidentialGrant->label = Member::loggedIn()->language()->addToStack('oauth_grant_types');
|
||||
$form->add( $confidentialGrant );
|
||||
$publicGrant = new \IPS\Helpers\Form\CheckboxSet( 'oauth_grant_types_public', $this->client_id ? explode( ',', $this->grant_types ) : array( 'implicit' ), NULL, array(
|
||||
$publicGrant = new CheckboxSet( 'oauth_grant_types_public', $this->client_id ? explode( ',', $this->grant_types ) : array( 'implicit' ), NULL, array(
|
||||
'options' => array(
|
||||
'authorization_code' => 'grant_type_authorization_code',
|
||||
'implicit' => 'grant_type_implicit',
|
||||
@@ -182,85 +209,86 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
'authorization_code' => array( 'oauth_pkce', 'oauth_use_refresh_tokens' )
|
||||
)
|
||||
), function( $val ) {
|
||||
if ( !$val and \IPS\Request::i()->oauth_client_type === 'public' ) {
|
||||
throw new \DomainException('form_required');
|
||||
if ( !$val and Request::i()->oauth_client_type === 'public' ) {
|
||||
throw new DomainException('form_required');
|
||||
}
|
||||
}, NULL, NULL, 'oauth_grant_types_public' );
|
||||
$publicGrant->label = \IPS\Member::loggedIn()->language()->addToStack('oauth_grant_types');
|
||||
$publicGrant->label = Member::loggedIn()->language()->addToStack('oauth_grant_types');
|
||||
$form->add( $publicGrant );
|
||||
$redirectUris = json_decode( $this->redirect_uris, TRUE );
|
||||
$form->add( new \IPS\Helpers\Form\Url( 'oauth_invision_endpoint', isset( $redirectUris[0] ) ? preg_replace( '#/oauth/callback/$#i', '/', $redirectUris[0] ) : NULL, NULL, array( 'placeholder' => 'https://othercommunity.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
|
||||
if ( !$val and \IPS\Request::i()->oauth_client_type == 'invision' ) {
|
||||
throw new \DomainException('form_required');
|
||||
$form->add( new FormUrl( 'oauth_invision_endpoint', isset( $redirectUris[0] ) ? preg_replace( '#/oauth/callback/$#i', '/', $redirectUris[0] ) : NULL, NULL, array( 'placeholder' => 'https://othercommunity.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
|
||||
if ( !$val and Request::i()->oauth_client_type == 'invision' ) {
|
||||
throw new DomainException('form_required');
|
||||
}
|
||||
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
|
||||
throw new \DomainException('oauth_redirect_uris_no_fragment');
|
||||
if ( $val and $val instanceof Url and $val->data[ Url::COMPONENT_FRAGMENT ] ) {
|
||||
throw new DomainException('oauth_redirect_uris_no_fragment');
|
||||
}
|
||||
if ( $val and rtrim( (string) $val, '/' ) === rtrim( \IPS\Settings::i()->base_url, '/' ) ) {
|
||||
throw new \DomainException('oauth_invision_endpoint_internal');
|
||||
if ( $val and rtrim( (string) $val, '/' ) === rtrim( Settings::i()->base_url, '/' ) ) {
|
||||
throw new DomainException('oauth_invision_endpoint_internal');
|
||||
}
|
||||
}, NULL, NULL, 'oauth_invision_endpoint' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Url( 'oauth_wordpress_endpoint', isset( $redirectUris[0] ) ? $redirectUris[0] : NULL, NULL, array( 'placeholder' => 'https://wordpress.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
|
||||
if ( !$val and \IPS\Request::i()->oauth_client_type == 'wordpress' ) {
|
||||
throw new \DomainException('form_required');
|
||||
$form->add( new FormUrl( 'oauth_wordpress_endpoint', $redirectUris[0] ?? NULL, NULL, array( 'placeholder' => 'https://wordpress.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
|
||||
if ( !$val and Request::i()->oauth_client_type == 'wordpress' ) {
|
||||
throw new DomainException('form_required');
|
||||
}
|
||||
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
|
||||
throw new \DomainException('oauth_redirect_uris_no_fragment');
|
||||
if ( $val and $val instanceof Url and $val->data[ Url::COMPONENT_FRAGMENT ] ) {
|
||||
throw new DomainException('oauth_redirect_uris_no_fragment');
|
||||
}
|
||||
}, NULL, NULL, 'oauth_wordpress_endpoint' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_pkce', $this->pkce ?: 'none', FALSE, array( 'options' => array( 'S256' => 'oauth_pkce_256', 'plain' => 'oauth_pkce_plain', 'none' => 'oauth_pkce_none' ) ), NULL, NULL, NULL, 'oauth_pkce' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Stack( 'oauth_redirect_uris', $redirectUris, NULL, array( 'stackFieldType' => 'Url', 'placeholder' => 'https://www.example.com/redirect_uri', 'allowedProtocols' => NULL ), function( $val ) {
|
||||
if ( !\in_array( \IPS\Request::i()->oauth_client_type, array('invision', 'wordpress') ) ) {
|
||||
$chosenGrantTypes = \IPS\Request::i()->oauth_client_type === 'public' ? \IPS\Request::i()->oauth_grant_types_public : \IPS\Request::i()->oauth_grant_types_confidential;
|
||||
$form->add( new Radio( 'oauth_pkce', $this->pkce ?: 'none', FALSE, array( 'options' => array( 'S256' => 'oauth_pkce_256', 'plain' => 'oauth_pkce_plain', 'none' => 'oauth_pkce_none' ) ), NULL, NULL, NULL, 'oauth_pkce' ) );
|
||||
$form->add( new Stack( 'oauth_redirect_uris', $redirectUris, NULL, array( 'stackFieldType' => 'Url', 'placeholder' => 'https://www.example.com/redirect_uri', 'allowedProtocols' => NULL ), function( $val ) {
|
||||
if ( !in_array( Request::i()->oauth_client_type, array('invision', 'wordpress') ) ) {
|
||||
$chosenGrantTypes = Request::i()->oauth_client_type === 'public' ? Request::i()->oauth_grant_types_public : Request::i()->oauth_grant_types_confidential;
|
||||
if ( !$val and ( isset( $chosenGrantTypes['authorization_code'] ) or isset( $chosenGrantTypes['implicit'] ) ) ) {
|
||||
throw new \DomainException('form_required');
|
||||
throw new DomainException('form_required');
|
||||
}
|
||||
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
|
||||
throw new \DomainException('oauth_redirect_uris_no_fragment');
|
||||
if ( $val and $val instanceof Url and $val->data[ Url::COMPONENT_FRAGMENT ] ) {
|
||||
throw new DomainException('oauth_redirect_uris_no_fragment');
|
||||
}
|
||||
}
|
||||
}, NULL, NULL, 'oauth_redirect_uris' ) );
|
||||
|
||||
$form->addHeader('oauth_authorization_screen');
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_prompt', $this->prompt, FALSE, array( 'options' => array( 'none' => 'oauth_prompt_none', 'automatic' => 'oauth_prompt_automatic', 'reauthorize' => 'oauth_prompt_reauthorize', 'login' => 'oauth_prompt_login' ) ) ) );
|
||||
$form->add( new Radio( 'oauth_prompt', $this->prompt, FALSE, array( 'options' => array( 'none' => 'oauth_prompt_none', 'automatic' => 'oauth_prompt_automatic', 'reauthorize' => 'oauth_prompt_reauthorize', 'login' => 'oauth_prompt_login' ) ) ) );
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_choose_scopes', $this->choose_scopes, FALSE, array(), NULL, NULL, NULL, 'oauth_choose_scopes' ) );
|
||||
$form->add( new YesNo( 'oauth_choose_scopes', $this->choose_scopes, FALSE, array(), NULL, NULL, NULL, 'oauth_choose_scopes' ) );
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_ucp', $this->ucp, FALSE ) );
|
||||
$form->add( new YesNo( 'oauth_ucp', $this->ucp, FALSE ) );
|
||||
|
||||
$form->addHeader('oauth_access_tokens');
|
||||
$form->add( new \IPS\Helpers\Form\Interval( 'oauth_access_token_length', $this->access_token_length, NULL, array( 'valueAs' => \IPS\Helpers\Form\Interval::HOURS, 'unlimited' => 0, 'unlimitedLang' => 'forever' ), NULL, NULL, NULL, 'oauth_access_token_length' ) );
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_use_refresh_tokens', $this->use_refresh_tokens, NULL, array( 'togglesOn' => array( 'oauth_refresh_token_length' ) ), NULL, NULL, NULL, 'oauth_use_refresh_tokens' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Interval( 'oauth_refresh_token_length', $this->refresh_token_length, NULL, array( 'valueAs' => \IPS\Helpers\Form\Interval::DAYS, 'unlimited' => 0, 'unlimitedLang' => 'forever' ), NULL, NULL, NULL, 'oauth_refresh_token_length' ) );
|
||||
$form->add( new Interval( 'oauth_access_token_length', $this->access_token_length, NULL, array( 'valueAs' => Interval::HOURS, 'unlimited' => 0, 'unlimitedLang' => 'forever' ), NULL, NULL, NULL, 'oauth_access_token_length' ) );
|
||||
$form->add( new YesNo( 'oauth_use_refresh_tokens', $this->use_refresh_tokens, NULL, array( 'togglesOn' => array( 'oauth_refresh_token_length' ) ), NULL, NULL, NULL, 'oauth_use_refresh_tokens' ) );
|
||||
$form->add( new Interval( 'oauth_refresh_token_length', $this->refresh_token_length, NULL, array( 'valueAs' => Interval::DAYS, 'unlimited' => 0, 'unlimitedLang' => 'forever' ), NULL, NULL, NULL, 'oauth_refresh_token_length' ) );
|
||||
|
||||
$form->addTab('oauth_scopes');
|
||||
$form->addMessage('oauth_scopes_blurb');
|
||||
$matrix = new \IPS\Helpers\Form\Matrix;
|
||||
$matrix = new Matrix;
|
||||
$matrix->classes[] = 'cApiPermissionsMatrix';
|
||||
$matrix->langPrefix = 'oauth_scope_';
|
||||
$matrix->columns = array(
|
||||
'name' => function( $key, $value, $data )
|
||||
{
|
||||
return new \IPS\Helpers\Form\Custom( $key, $value, FALSE, array(
|
||||
return new Custom( $key, $value, FALSE, array(
|
||||
'getHtml' => function( $field )
|
||||
{
|
||||
return \IPS\Theme::i()->getTemplate( 'api' )->oauthScopeField( $field->name, $field->value );
|
||||
return Theme::i()->getTemplate( 'api' )->oauthScopeField( $field->name, $field->value );
|
||||
}
|
||||
) );
|
||||
},
|
||||
'endpoints' => function( $key, $value, $data )
|
||||
{
|
||||
return new \IPS\Helpers\Form\Custom( $key, $value ?: array(), FALSE, array(
|
||||
return new Custom( $key, $value ?: array(), FALSE, array(
|
||||
'getHtml' => function( $field )
|
||||
{
|
||||
$endpoints = \IPS\Api\Controller::getAllEndpoints();
|
||||
$endpoints = Controller::getAllEndpoints();
|
||||
$endpointTree = [];
|
||||
foreach ( $endpoints as $key => $endpoint )
|
||||
{
|
||||
$pieces = explode('/', $key);
|
||||
$endpointTree[ $pieces[0] ][ $pieces[1] ][ $key ] = $endpoint;
|
||||
}
|
||||
|
||||
return \IPS\Theme::i()->getTemplate( 'api' )->permissionsFieldHtml( $endpointTree, $field->name, $field->value );
|
||||
return Theme::i()->getTemplate( 'api' )->permissionsFieldHtml( $endpointTree, $field->name, $field->value );
|
||||
}
|
||||
) );
|
||||
}
|
||||
@@ -268,13 +296,13 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
if ( !$this->client_id )
|
||||
{
|
||||
$matrix->rows[] = array(
|
||||
'name' => array( 'key' => 'profile', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_profile') ),
|
||||
'name' => array( 'key' => 'profile', 'desc' => Member::loggedIn()->language()->get('oauth_default_scope_profile') ),
|
||||
'endpoints' => array(
|
||||
'core/me/GETindex' => array( 'access' => TRUE, 'log' => FALSE ),
|
||||
)
|
||||
);
|
||||
$matrix->rows[] = array(
|
||||
'name' => array( 'key' => 'email', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_email') ),
|
||||
'name' => array( 'key' => 'email', 'desc' => Member::loggedIn()->language()->get('oauth_default_scope_email') ),
|
||||
'endpoints' => array(
|
||||
'core/me/GETitem' => array( 'access' => TRUE, 'log' => FALSE ),
|
||||
)
|
||||
@@ -296,7 +324,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
/**
|
||||
* @brief Temporary storage for the client secret
|
||||
*/
|
||||
public $_clientSecret;
|
||||
public ?string $_clientSecret = null;
|
||||
|
||||
/**
|
||||
* [Node] Format form values from add/edit form for save
|
||||
@@ -304,10 +332,10 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
* @param array $values Values from the form
|
||||
* @return array
|
||||
*/
|
||||
public function formatFormValues( $values )
|
||||
public function formatFormValues( array $values ): array
|
||||
{
|
||||
/* Normalise the settings */
|
||||
$originalClientType = isset( $values['oauth_client_type'] ) ? $values['oauth_client_type'] : $this->type;
|
||||
$originalClientType = $values['oauth_client_type'] ?? $this->type;
|
||||
|
||||
if ( $values['oauth_client_type'] === 'invision' )
|
||||
{
|
||||
@@ -321,13 +349,13 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
$values['oauth_api_access'] = 'rest';
|
||||
$values['scopes'] = array(
|
||||
array(
|
||||
'name' => array( 'key' => 'profile', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_profile') ),
|
||||
'name' => array( 'key' => 'profile', 'desc' => Member::loggedIn()->language()->get('oauth_default_scope_profile') ),
|
||||
'endpoints' => array(
|
||||
'core/me/GETindex' => array( 'access' => TRUE, 'log' => FALSE ),
|
||||
)
|
||||
),
|
||||
array(
|
||||
'name' => array( 'key' => 'email', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_email') ),
|
||||
'name' => array( 'key' => 'email', 'desc' => Member::loggedIn()->language()->get('oauth_default_scope_email') ),
|
||||
'endpoints' => array(
|
||||
'core/me/GETitem' => array( 'access' => TRUE, 'log' => FALSE ),
|
||||
)
|
||||
@@ -348,7 +376,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
$values['oauth_api_access'] = 'rest';
|
||||
$values['scopes'] = array(
|
||||
array(
|
||||
'name' => array( 'key' => 'email', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_email') ),
|
||||
'name' => array( 'key' => 'email', 'desc' => Member::loggedIn()->language()->get('oauth_default_scope_email') ),
|
||||
'endpoints' => array(
|
||||
'core/me/GETindex' => array( 'access' => TRUE, 'log' => FALSE ),
|
||||
'core/me/GETitem' => array( 'access' => TRUE, 'log' => FALSE ),
|
||||
@@ -376,9 +404,9 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
{
|
||||
do
|
||||
{
|
||||
$values['oauth_client_id'] = \IPS\Login::generateRandomString( 32 );
|
||||
$values['oauth_client_id'] = Login::generateRandomString( 32 );
|
||||
}
|
||||
while ( \IPS\Db::i()->select( 'COUNT(*)', 'core_oauth_clients', array( 'oauth_client_id=?', $values['oauth_client_id'] ) )->first() );
|
||||
while ( Db::i()->select( 'COUNT(*)', 'core_oauth_clients', array( 'oauth_client_id=?', $values['oauth_client_id'] ) )->first() );
|
||||
}
|
||||
|
||||
/* And secret */
|
||||
@@ -386,7 +414,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
{
|
||||
if ( !$this->client_secret )
|
||||
{
|
||||
$this->_clientSecret = \IPS\Login::generateRandomString( 48 );
|
||||
$this->_clientSecret = Login::generateRandomString( 48 );
|
||||
$values['oauth_client_secret'] = password_hash( $this->_clientSecret, PASSWORD_DEFAULT );
|
||||
}
|
||||
$values['oauth_grant_types'] = $values['oauth_grant_types_confidential'];
|
||||
@@ -401,11 +429,11 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
|
||||
/* Save the name */
|
||||
$clientId = $this->client_id ?: $values['oauth_client_id'];
|
||||
\IPS\Lang::saveCustom( 'core', "core_oauth_client_{$clientId}", $values['oauth_client_name'] );
|
||||
Lang::saveCustom( 'core', "core_oauth_client_{$clientId}", $values['oauth_client_name'] );
|
||||
unset( $values['oauth_client_name'] );
|
||||
|
||||
/* Redirect URIs */
|
||||
if ( \in_array( $originalClientType, array( 'public', 'invision', 'wordpress' ) ) or \in_array( 'authorization_code', $values['oauth_grant_types'] ) or \in_array( 'implicit', $values['oauth_grant_types'] ) )
|
||||
if ( in_array( $originalClientType, array( 'public', 'invision', 'wordpress' ) ) or in_array( 'authorization_code', $values['oauth_grant_types'] ) or in_array( 'implicit', $values['oauth_grant_types'] ) )
|
||||
{
|
||||
$values['oauth_redirect_uris'] = json_encode( array_map( function( $url ) { return (string) $url; }, $values['oauth_redirect_uris'] ) );
|
||||
}
|
||||
@@ -422,7 +450,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
if ( $row['name']['key'] )
|
||||
{
|
||||
$scopes[ $row['name']['key'] ] = array(
|
||||
'description' => isset( $row['name']['desc'] ) ? $row['name']['desc'] : NULL,
|
||||
'description' => $row['name']['desc'] ?? NULL,
|
||||
'endpoints' => $row['endpoints']
|
||||
);
|
||||
}
|
||||
@@ -439,10 +467,10 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
*
|
||||
* @return NULL|array Null for no badge, or an array of badge data (0 => CSS class type, 1 => language string, 2 => optional raw HTML to show instead of language string)
|
||||
*/
|
||||
public function get__badge()
|
||||
public function get__badge(): ?array
|
||||
{
|
||||
return array(
|
||||
0 => 'ipsBadge ipsBadge_neutral ipsPos_right ipsMargin_right:half',
|
||||
0 => 'ipsBadge ipsBadge--neutral i-float_end i-margin-end_icon',
|
||||
1 => 'api_access_' . $this->api_access,
|
||||
);
|
||||
}
|
||||
@@ -452,7 +480,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
*
|
||||
* @return string|null
|
||||
*/
|
||||
protected function get__description()
|
||||
protected function get__description(): ?string
|
||||
{
|
||||
return $this->client_id;
|
||||
}
|
||||
@@ -462,7 +490,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
*
|
||||
* @return bool
|
||||
*/
|
||||
public function canCopy()
|
||||
public function canCopy(): bool
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
@@ -472,21 +500,21 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
* Example code explains return value
|
||||
*
|
||||
* @code
|
||||
array(
|
||||
array(
|
||||
'icon' => 'plus-circle', // Name of FontAwesome icon to use
|
||||
'title' => 'foo', // Language key to use for button's title parameter
|
||||
'link' => \IPS\Http\Url::internal( 'app=foo...' ) // URI to link to
|
||||
'class' => 'modalLink' // CSS Class to use on link (Optional)
|
||||
),
|
||||
... // Additional buttons
|
||||
);
|
||||
* array(
|
||||
* array(
|
||||
* 'icon' => 'plus-circle', // Name of FontAwesome icon to use
|
||||
* 'title' => 'foo', // Language key to use for button's title parameter
|
||||
* 'link' => \IPS\Http\Url::internal( 'app=foo...' ) // URI to link to
|
||||
* 'class' => 'modalLink' // CSS Class to use on link (Optional)
|
||||
* ),
|
||||
* ... // Additional buttons
|
||||
* );
|
||||
* @endcode
|
||||
* @param string $url Base URL
|
||||
* @param Url $url Base URL
|
||||
* @param bool $subnode Is this a subnode?
|
||||
* @return array
|
||||
*/
|
||||
public function getButtons( $url, $subnode=FALSE )
|
||||
public function getButtons( Url $url, bool $subnode=FALSE ):array
|
||||
{
|
||||
$buttons = array();
|
||||
|
||||
@@ -496,7 +524,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
'link' => $url->setQueryString( array( 'do' => 'view', 'client_id' => $this->client_id ) )
|
||||
);
|
||||
|
||||
if ( \IPS\Member::loggedIn()->hasAcpRestriction( 'core', 'applications', 'oauth_tokens' ) )
|
||||
if ( Member::loggedIn()->hasAcpRestriction( 'core', 'applications', 'oauth_tokens' ) )
|
||||
{
|
||||
$buttons['tokens'] = array(
|
||||
'icon' => 'key',
|
||||
@@ -508,37 +536,37 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
$_parentButtons = parent::getButtons( $url, $subnode );
|
||||
if ( isset( $_parentButtons['delete'] ) )
|
||||
{
|
||||
$_parentButtons['delete']['data'] = array( 'confirm' => '', 'confirmSubMessage' => \IPS\Member::loggedIn()->language()->addToStack('oauth_client_delete_warning') );
|
||||
$_parentButtons['delete']['data'] = array( 'confirm' => '', 'confirmSubMessage' => Member::loggedIn()->language()->addToStack('oauth_client_delete_warning') );
|
||||
}
|
||||
|
||||
return $buttons + $_parentButtons;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Generate or renew an access token
|
||||
*
|
||||
* @param \IPS\Member|NULL $member The member or NULL for client_credentials
|
||||
* @param array|null $scopes Array of scopes or NULL if none were requested
|
||||
* @param string $grantType Type of grant
|
||||
* @param bool $skipRefreshToken If TRUE, will not generate a refresh token (for example, when using implicit grant type)
|
||||
* @param string|NULL $authorizationCode The authorization code which generated the token, if applicable
|
||||
* @param string|NULL $userAgent The user agent that the user performed authentication on, if known
|
||||
* @param string|NULL $issueUserAgent The user agent that the access token was issued to, if known
|
||||
* @param \IPS\Member\Device|NULL $device The device used to obtain this access token, if known
|
||||
* @param array $tokenToRefresh If we are refreshing, the existing access token to refresh
|
||||
* @return array
|
||||
* @param Member|NULL $member The member or NULL for client_credentials
|
||||
* @param array|null $scopes Array of scopes or NULL if none were requested
|
||||
* @param string $grantType Type of grant
|
||||
* @param bool $skipRefreshToken If TRUE, will not generate a refresh token (for example, when using implicit grant type)
|
||||
* @param string|NULL $authorizationCode The authorization code which generated the token, if applicable
|
||||
* @param string|null $authUserAgent
|
||||
* @param string|null $grantUserAgent
|
||||
* @param Device|NULL $device The device used to obtain this access token, if known
|
||||
* @param array|null $tokenToRefresh If we are refreshing, the existing access token to refresh
|
||||
* @return array
|
||||
*/
|
||||
public function generateAccessToken( ?\IPS\Member $member, $scopes, $grantType, $skipRefreshToken = FALSE, $authorizationCode = NULL, $authUserAgent = NULL, $grantUserAgent = NULL, \IPS\Member\Device $device = NULL, $tokenToRefresh = NULL )
|
||||
public function generateAccessToken( ?Member $member, ?array $scopes, string $grantType, bool $skipRefreshToken = FALSE, ?string $authorizationCode = NULL, ?string $authUserAgent = NULL, ?string $grantUserAgent = NULL, ?Device $device = NULL, ?array $tokenToRefresh = NULL ) : array
|
||||
{
|
||||
do
|
||||
{
|
||||
$accessToken = \IPS\Login::generateRandomString( 64 );
|
||||
$accessToken = Login::generateRandomString( 64 );
|
||||
}
|
||||
while ( $this->validateAccessToken( $accessToken ) );
|
||||
|
||||
$data = array(
|
||||
'client_id' => $this->client_id,
|
||||
'member_id' => $member ? $member->member_id : NULL,
|
||||
'member_id' => $member?->member_id,
|
||||
'access_token' => $accessToken,
|
||||
'access_token_expires' => $this->access_token_length ? ( time() + ( $this->access_token_length * 3600 ) ) : NULL,
|
||||
'refresh_token' => NULL,
|
||||
@@ -548,7 +576,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
'issued' => time(),
|
||||
'auth_user_agent' => $authUserAgent,
|
||||
'issue_user_agent' => $grantUserAgent,
|
||||
'device_key' => $device ? $device->device_key : NULL,
|
||||
'device_key' => $device?->device_key,
|
||||
'status' => 'active',
|
||||
);
|
||||
|
||||
@@ -558,7 +586,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
{
|
||||
do
|
||||
{
|
||||
$data['refresh_token'] = \IPS\Login::generateRandomString( 64 );
|
||||
$data['refresh_token'] = Login::generateRandomString( 64 );
|
||||
}
|
||||
while ( $this->validateRefreshToken( $data['refresh_token'] ) );
|
||||
|
||||
@@ -575,12 +603,12 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
|
||||
if ( $grantType === 'refresh_token' and $tokenToRefresh )
|
||||
{
|
||||
\IPS\Db::i()->update( 'core_oauth_server_access_tokens', array( 'status' => 'revoked' ), array( 'client_id=? AND access_token=?', $tokenToRefresh['client_id'], $tokenToRefresh['access_token'] ) );
|
||||
\IPS\Db::i()->insert( 'core_oauth_server_access_tokens', $data );
|
||||
Db::i()->update( 'core_oauth_server_access_tokens', array( 'status' => 'revoked' ), array( 'client_id=? AND access_token=?', $tokenToRefresh['client_id'], $tokenToRefresh['access_token'] ) );
|
||||
Db::i()->insert( 'core_oauth_server_access_tokens', $data );
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Db::i()->insert( 'core_oauth_server_access_tokens', $data );
|
||||
Db::i()->insert( 'core_oauth_server_access_tokens', $data );
|
||||
if ( $member )
|
||||
{
|
||||
$member->logHistory( 'core', 'oauth', array( 'type' => 'issued_access_token', 'client' => $this->client_id, 'grant' => $grantType, 'scopes' => $scopes ), FALSE );
|
||||
@@ -591,7 +619,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
{
|
||||
$device->last_seen = time();
|
||||
$device->save();
|
||||
$device->logIpAddress( \IPS\Request::i()->ipAddress() );
|
||||
$device->logIpAddress( Request::i()->ipAddress() );
|
||||
}
|
||||
|
||||
$data['access_token'] = $this->client_id . '_' . $data['access_token'];
|
||||
@@ -603,27 +631,27 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
* Get access token details, checking it isn't expired
|
||||
*
|
||||
* @param string $accessToken The access token
|
||||
* @return \IPS\Member|NULL
|
||||
* @throws \UnderflowException
|
||||
* @throws \IPS\Api\Exception
|
||||
* @return array
|
||||
* @throws UnderflowException
|
||||
* @throws Exception
|
||||
*/
|
||||
public static function accessTokenDetails( $accessToken )
|
||||
public static function accessTokenDetails( string $accessToken ) : array
|
||||
{
|
||||
$exploded = explode( '_', $accessToken );
|
||||
|
||||
if ( !isset( $exploded[0] ) or !isset( $exploded[1] ) )
|
||||
{
|
||||
throw new \UnderflowException;
|
||||
throw new UnderflowException;
|
||||
}
|
||||
|
||||
$return = \IPS\Db::i()->select( '*', 'core_oauth_server_access_tokens', array( 'client_id=? AND access_token=?', $exploded[0], $exploded[1] ) )->first();
|
||||
$return = Db::i()->select( '*', 'core_oauth_server_access_tokens', array( 'client_id=? AND access_token=?', $exploded[0], $exploded[1] ) )->first();
|
||||
if ( $return['status'] == 'revoked' )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'REVOKED_ACCESS_TOKEN', '1S290/F', 401, 'invalid_token' );
|
||||
throw new Exception( 'REVOKED_ACCESS_TOKEN', '1S290/F', 401, 'invalid_token' );
|
||||
}
|
||||
if ( $return['access_token_expires'] and $return['access_token_expires'] < time() )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'EXPIRED_ACCESS_TOKEN', '1S290/E', 401, 'invalid_token' );
|
||||
throw new Exception( 'EXPIRED_ACCESS_TOKEN', '1S290/E', 401, 'invalid_token' );
|
||||
}
|
||||
|
||||
return $return;
|
||||
@@ -633,41 +661,43 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
* Validate an access token
|
||||
*
|
||||
* @param string $accessToken The access token
|
||||
* @return \IPS\Member|NULL
|
||||
* @return Member|NULL
|
||||
*/
|
||||
public function validateAccessToken( $accessToken )
|
||||
public function validateAccessToken( string $accessToken ) : ?Member
|
||||
{
|
||||
try
|
||||
{
|
||||
$row = \IPS\Db::i()->select( array( 'member_id', 'access_token_expires' ), 'core_oauth_server_access_tokens', array( 'client_id=? AND access_token=?', $this->client_id, $accessToken ) )->first();
|
||||
$row = Db::i()->select( array( 'member_id', 'access_token_expires' ), 'core_oauth_server_access_tokens', array( 'client_id=? AND access_token=?', $this->client_id, $accessToken ) )->first();
|
||||
if ( $row['status'] == 'revoked' )
|
||||
{
|
||||
return;
|
||||
return null;
|
||||
}
|
||||
if ( $row['access_token_expires'] and $row['access_token_expires'] < time() )
|
||||
{
|
||||
return;
|
||||
return null;
|
||||
}
|
||||
|
||||
$member = \IPS\Member::load( $row['member_id'] );
|
||||
$member = Member::load( $row['member_id'] );
|
||||
if ( $member->member_id )
|
||||
{
|
||||
return $member;
|
||||
}
|
||||
}
|
||||
catch ( \UnderflowException $e ) { }
|
||||
catch ( UnderflowException $e ) { }
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get an existing access token with particular scopes, if they exist
|
||||
*
|
||||
* @param \IPS\Member|NULL $member The member or NULL for client_credentials
|
||||
* @param Member|NULL $member The member or NULL for client_credentials
|
||||
* @param array $scopes The scopes
|
||||
* @return array|NULL
|
||||
*/
|
||||
public function getAccessToken( \IPS\Member $member = NULL, $scopes = array() )
|
||||
public function getAccessToken( ?Member $member = NULL, array $scopes = array() ) : ?array
|
||||
{
|
||||
foreach ( \IPS\Db::i()->select( '*', 'core_oauth_server_access_tokens', array( 'client_id=? AND member_id=?', $this->client_id, $member->member_id ) ) as $row )
|
||||
foreach ( Db::i()->select( '*', 'core_oauth_server_access_tokens', array( 'client_id=? AND member_id=?', $this->client_id, $member->member_id ) ) as $row )
|
||||
{
|
||||
if ( $row['status'] == 'revoked' )
|
||||
{
|
||||
@@ -688,13 +718,15 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
}
|
||||
}
|
||||
|
||||
if ( \count( array_diff( $scopes, $row['scope'] ? json_decode( $row['scope'] ) : array() ) ) )
|
||||
if ( count( array_diff( $scopes, $row['scope'] ? json_decode( $row['scope'] ) : array() ) ) )
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
return $row;
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -703,23 +735,25 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
* @param string $refreshToken The refresh token
|
||||
* @return array|NULL
|
||||
*/
|
||||
public function validateRefreshToken( $refreshToken )
|
||||
public function validateRefreshToken( string $refreshToken ) : ?array
|
||||
{
|
||||
try
|
||||
{
|
||||
$row = \IPS\Db::i()->select( '*', 'core_oauth_server_access_tokens', array( 'client_id=? AND refresh_token=?', $this->client_id, $refreshToken ) )->first();
|
||||
$row = Db::i()->select( '*', 'core_oauth_server_access_tokens', array( 'client_id=? AND refresh_token=?', $this->client_id, $refreshToken ) )->first();
|
||||
if ( $row['status'] == 'revoked' )
|
||||
{
|
||||
return;
|
||||
return null;
|
||||
}
|
||||
if ( $row['refresh_token_expires'] and $row['refresh_token_expires'] < time() )
|
||||
{
|
||||
return;
|
||||
return null;
|
||||
}
|
||||
|
||||
return $row;
|
||||
}
|
||||
catch ( \UnderflowException $e ) { }
|
||||
catch ( UnderflowException $e ) { }
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -731,7 +765,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
* @param string $method Method
|
||||
* @return string|NULL
|
||||
*/
|
||||
public function scopesCanAccess( $authorizedScopes, $app, $controller, $method )
|
||||
public function scopesCanAccess( array $authorizedScopes, string $app, string $controller, string $method ) : ?string
|
||||
{
|
||||
$scopes = $this->scopes ? json_decode( $this->scopes, TRUE ) : array();
|
||||
|
||||
@@ -739,7 +773,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
{
|
||||
if ( isset( $scopes[ $scope ] ) )
|
||||
{
|
||||
if ( isset( $scopes[ $scope ]['endpoints']["{$app}/{$controller}/{$method}"] ) and $scopes[ $scope ]['endpoints']["{$app}/{$controller}/{$method}"]['access'] == TRUE )
|
||||
if ( isset( $scopes[ $scope ]['endpoints']["{$app}/{$controller}/{$method}"] ) and $scopes[$scope]['endpoints']["{$app}/{$controller}/{$method}"]['access'] )
|
||||
{
|
||||
return $scope;
|
||||
}
|
||||
@@ -758,7 +792,7 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
* @param string $method Method
|
||||
* @return bool
|
||||
*/
|
||||
public function scopeShouldLog( $scope, $app, $controller, $method )
|
||||
public function scopeShouldLog( string $scope, string $app, string $controller, string $method ) : bool
|
||||
{
|
||||
$scopes = $this->scopes ? json_decode( $this->scopes, TRUE ) : array();
|
||||
return isset( $scopes[ $scope ]['endpoints']["{$app}/{$controller}/{$method}"] ) and isset( $scopes[ $scope ]['endpoints']["{$app}/{$controller}/{$method}"]['log'] ) and $scopes[ $scope ]['endpoints']["{$app}/{$controller}/{$method}"]['log'] == TRUE;
|
||||
@@ -767,13 +801,13 @@ class _OAuthClient extends \IPS\Node\Model
|
||||
/**
|
||||
* [ActiveRecord] Delete Record
|
||||
*
|
||||
* @return void
|
||||
* @return void
|
||||
*/
|
||||
public function delete()
|
||||
public function delete(): void
|
||||
{
|
||||
\IPS\Db::i()->delete( 'core_oauth_server_access_tokens', array( 'client_id=?', $this->client_id ) );
|
||||
\IPS\Db::i()->delete( 'core_oauth_server_authorization_codes', array( 'client_id=?', $this->client_id ) );
|
||||
Db::i()->delete( 'core_oauth_server_access_tokens', array( 'client_id=?', $this->client_id ) );
|
||||
Db::i()->delete( 'core_oauth_server_authorization_codes', array( 'client_id=?', $this->client_id ) );
|
||||
|
||||
return parent::delete();
|
||||
parent::delete();
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user