Version 5.0.0 beta 1
This commit is contained in:
1 parent
25ddeb65d6
commit
15c7beabc5
6736 files changed
+627902
-497943
No files matched your search
@@ -12,28 +12,53 @@
|
||||
namespace IPS\Login\Handler\OAuth2;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
|
||||
use DomainException;
|
||||
use IPS\File;
|
||||
use IPS\Helpers\Form\Color;
|
||||
use IPS\Helpers\Form\Radio;
|
||||
use IPS\Helpers\Form\Select;
|
||||
use IPS\Helpers\Form\Stack;
|
||||
use IPS\Helpers\Form\Text;
|
||||
use IPS\Helpers\Form\Translatable;
|
||||
use IPS\Helpers\Form\Upload;
|
||||
use IPS\Helpers\Form\Url as FormUrl;
|
||||
use IPS\Http\Url;
|
||||
use IPS\Lang;
|
||||
use IPS\Log;
|
||||
use IPS\Login;
|
||||
use IPS\Login\Exception;
|
||||
use IPS\Login\Handler\OAuth2;
|
||||
use IPS\Member;
|
||||
use IPS\Settings;
|
||||
use RuntimeException;
|
||||
use function defined;
|
||||
use function is_array;
|
||||
use function is_string;
|
||||
use const IPS\OAUTH_REQUIRES_HTTPS;
|
||||
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Custom OAuth 2 Login Handler
|
||||
*/
|
||||
class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
class Custom extends OAuth2
|
||||
{
|
||||
/**
|
||||
* @brief Can we have multiple instances of this handler?
|
||||
*/
|
||||
public static $allowMultiple = TRUE;
|
||||
public static bool $allowMultiple = TRUE;
|
||||
|
||||
/**
|
||||
* Get title
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public static function getTitle()
|
||||
public static function getTitle(): string
|
||||
{
|
||||
return 'login_handler_custom_oauth';
|
||||
}
|
||||
@@ -46,13 +71,13 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
return array( 'savekey' => new \IPS\Helpers\Form\[Type]( ... ), ... );
|
||||
* @endcode
|
||||
*/
|
||||
public function acpForm()
|
||||
public function acpForm(): array
|
||||
{
|
||||
$return = array();
|
||||
|
||||
$return[] = array( 'login_handler_oauth_settings', 'login_handler_custom_oauth_info' );
|
||||
|
||||
$return['grant_type'] = new \IPS\Helpers\Form\Radio( 'oauth_custom_grant_type', isset( $this->settings['grant_type'] ) ? $this->settings['grant_type'] : 'authorization_code', TRUE, array(
|
||||
$return['grant_type'] = new Radio( 'oauth_custom_grant_type', $this->settings['grant_type'] ?? 'authorization_code', TRUE, array(
|
||||
'options' => array(
|
||||
'authorization_code' => 'client_grant_type_authorization_code',
|
||||
'implicit' => 'client_grant_type_implicit',
|
||||
@@ -73,59 +98,59 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
{
|
||||
$active = 'accountManagementSettings';
|
||||
}
|
||||
if ( !\is_string( $v ) and !\is_array( $v ) )
|
||||
if ( !is_string( $v ) and !is_array( $v ) )
|
||||
{
|
||||
${$active}[ $k ] = $v;
|
||||
}
|
||||
}
|
||||
|
||||
$return['authentication_type'] = new \IPS\Helpers\Form\Radio( 'oauth_custom_authentication_type', isset( $this->settings['authentication_type'] ) ? $this->settings['authentication_type'] : static::AUTHENTICATE_HEADER, TRUE, array(
|
||||
$return['authentication_type'] = new Radio( 'oauth_custom_authentication_type', $this->settings['authentication_type'] ?? static::AUTHENTICATE_HEADER, TRUE, array(
|
||||
'options' => array(
|
||||
static::AUTHENTICATE_HEADER => 'oauth_custom_authentication_type_header',
|
||||
static::AUTHENTICATE_POST => 'oauth_custom_authentication_type_post',
|
||||
)
|
||||
) );
|
||||
|
||||
$return['scopes'] = new \IPS\Helpers\Form\Stack( 'oauth_scopes_to_request', isset( $this->settings['scopes'] ) ? $this->settings['scopes'] : array(), FALSE, array() );
|
||||
$return['scopes'] = new Stack( 'oauth_scopes_to_request', $this->settings['scopes'] ?? array(), FALSE, array() );
|
||||
|
||||
$authorizationEndpointValidation = function( $val )
|
||||
{
|
||||
if ( \IPS\OAUTH_REQUIRES_HTTPS and $val and $val instanceof \IPS\Http\Url )
|
||||
if ( OAUTH_REQUIRES_HTTPS and $val and $val instanceof Url )
|
||||
{
|
||||
if ( $val->data[ \IPS\Http\Url::COMPONENT_SCHEME ] !== 'https' )
|
||||
if ( $val->data[ Url::COMPONENT_SCHEME ] !== 'https' )
|
||||
{
|
||||
throw new \DomainException('authorization_endpoint_https');
|
||||
throw new DomainException('authorization_endpoint_https');
|
||||
}
|
||||
if ( $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] )
|
||||
if ( $val->data[ Url::COMPONENT_FRAGMENT ] )
|
||||
{
|
||||
throw new \DomainException('authorization_endpoint_fragment');
|
||||
throw new DomainException('authorization_endpoint_fragment');
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
$return['authorization_endpoint'] = new \IPS\Helpers\Form\Url( 'oauth_authorization_endpoint', isset( $this->settings['authorization_endpoint'] ) ? $this->settings['authorization_endpoint'] : NULL, NULL, array( 'placeholder' => 'https://example.com/oauth/authorize' ), $authorizationEndpointValidation, NULL, NULL, 'authorization_endpoint' );
|
||||
$return['authorization_endpoint_secure'] = new \IPS\Helpers\Form\Url( 'oauth_authorization_endpoint_secure', ( isset( $this->settings['authorization_endpoint_secure'] ) AND $this->settings['authorization_endpoint_secure'] ) ? $this->settings['authorization_endpoint_secure'] : NULL, NULL, array( 'nullLang' => 'oauth_authorization_endpoint_same', 'placeholder' => 'https://example.com/oauth/authorize/?prompt=login' ), $authorizationEndpointValidation, NULL, NULL, 'authorization_endpoint_secure' );
|
||||
$return['token_endpoint'] = new \IPS\Helpers\Form\Url( 'oauth_token_endpoint', isset( $this->settings['token_endpoint'] ) ? $this->settings['token_endpoint'] : NULL, TRUE, array( 'placeholder' => 'https://www.example.com/oauth/token' ) );
|
||||
$return['user_endpoint'] = new \IPS\Helpers\Form\Url( 'oauth_user_endpoint', isset( $this->settings['user_endpoint'] ) ? $this->settings['user_endpoint'] : NULL, TRUE, array( 'placeholder' => 'https://www.example.com/oauth/me' ) );
|
||||
$return['uid_field'] = new \IPS\Helpers\Form\Text( 'oauth_custom_uid_field', isset( $this->settings['uid_field'] ) ? $this->settings['uid_field'] : NULL, TRUE, array() );
|
||||
$return['name_field'] = new \IPS\Helpers\Form\Text( 'oauth_custom_name_field', isset( $this->settings['name_field'] ) ? $this->settings['name_field'] : NULL, FALSE, array(), NULL, NULL, NULL, 'login_real_name' );
|
||||
$return['email_field'] = new \IPS\Helpers\Form\Text( 'oauth_custom_email_field', isset( $this->settings['email_field'] ) ? $this->settings['email_field'] : NULL, FALSE, array(), NULL, NULL, NULL, 'login_real_email' );
|
||||
$return['photo_field'] = new \IPS\Helpers\Form\Text( 'oauth_custom_photo_field', isset( $this->settings['photo_field'] ) ? $this->settings['photo_field'] : NULL );
|
||||
if ( \IPS\Settings::i()->allow_forgot_password == 'normal' or \IPS\Settings::i()->allow_forgot_password == 'handler' )
|
||||
$return['authorization_endpoint'] = new FormUrl( 'oauth_authorization_endpoint', $this->settings['authorization_endpoint'] ?? NULL, NULL, array( 'placeholder' => 'https://example.com/oauth/authorize' ), $authorizationEndpointValidation, NULL, NULL, 'authorization_endpoint' );
|
||||
$return['authorization_endpoint_secure'] = new FormUrl( 'oauth_authorization_endpoint_secure', ( isset( $this->settings['authorization_endpoint_secure'] ) AND $this->settings['authorization_endpoint_secure'] ) ? $this->settings['authorization_endpoint_secure'] : NULL, NULL, array( 'nullLang' => 'oauth_authorization_endpoint_same', 'placeholder' => 'https://example.com/oauth/authorize/?prompt=login' ), $authorizationEndpointValidation, NULL, NULL, 'authorization_endpoint_secure' );
|
||||
$return['token_endpoint'] = new FormUrl( 'oauth_token_endpoint', $this->settings['token_endpoint'] ?? NULL, TRUE, array( 'placeholder' => 'https://www.example.com/oauth/token' ) );
|
||||
$return['user_endpoint'] = new FormUrl( 'oauth_user_endpoint', $this->settings['user_endpoint'] ?? NULL, TRUE, array( 'placeholder' => 'https://www.example.com/oauth/me' ) );
|
||||
$return['uid_field'] = new Text( 'oauth_custom_uid_field', $this->settings['uid_field'] ?? NULL, TRUE, array() );
|
||||
$return['name_field'] = new Text( 'oauth_custom_name_field', $this->settings['name_field'] ?? NULL, FALSE, array(), NULL, NULL, NULL, 'login_real_name' );
|
||||
$return['email_field'] = new Text( 'oauth_custom_email_field', $this->settings['email_field'] ?? NULL, FALSE, array(), NULL, NULL, NULL, 'login_real_email' );
|
||||
$return['photo_field'] = new Text( 'oauth_custom_photo_field', $this->settings['photo_field'] ?? NULL );
|
||||
if ( Settings::i()->allow_forgot_password == 'normal' or Settings::i()->allow_forgot_password == 'handler' )
|
||||
{
|
||||
$return['forgot_password_url'] = new \IPS\Helpers\Form\Url( 'handler_forgot_password_url', isset( $this->settings['forgot_password_url'] ) ? $this->settings['forgot_password_url'] : NULL, FALSE, array(), NULL, NULL, NULL, 'forgot_password_url' );
|
||||
\IPS\Member::loggedIn()->language()->words['handler_forgot_password_url_desc'] = \IPS\Member::loggedIn()->language()->addToStack( \IPS\Settings::i()->allow_forgot_password == 'normal' ? 'handler_forgot_password_url_desc_normal' : 'handler_forgot_password_url_deschandler' );
|
||||
$return['forgot_password_url'] = new FormUrl( 'handler_forgot_password_url', $this->settings['forgot_password_url'] ?? NULL, FALSE, array(), NULL, NULL, NULL, 'forgot_password_url' );
|
||||
Member::loggedIn()->language()->words['handler_forgot_password_url_desc'] = Member::loggedIn()->language()->addToStack( Settings::i()->allow_forgot_password == 'normal' ? 'handler_forgot_password_url_desc_normal' : 'handler_forgot_password_url_deschandler' );
|
||||
}
|
||||
|
||||
$return[] = 'login_handler_oauth_ui';
|
||||
$return['auth_types'] = new \IPS\Helpers\Form\Select( 'oauth_custom_auth_types', isset( $this->settings['auth_types'] ) ? $this->settings['auth_types'] : ( \IPS\Login::AUTH_TYPE_USERNAME + \IPS\Login::AUTH_TYPE_EMAIL ), TRUE, array( 'options' => array(
|
||||
\IPS\Login::AUTH_TYPE_USERNAME + \IPS\Login::AUTH_TYPE_EMAIL => 'username_or_email',
|
||||
\IPS\Login::AUTH_TYPE_EMAIL => 'email_address',
|
||||
\IPS\Login::AUTH_TYPE_USERNAME => 'username',
|
||||
$return['auth_types'] = new Select( 'oauth_custom_auth_types', $this->settings['auth_types'] ?? ( Login::AUTH_TYPE_USERNAME + Login::AUTH_TYPE_EMAIL ), TRUE, array( 'options' => array(
|
||||
Login::AUTH_TYPE_USERNAME + Login::AUTH_TYPE_EMAIL => 'username_or_email',
|
||||
Login::AUTH_TYPE_EMAIL => 'email_address',
|
||||
Login::AUTH_TYPE_USERNAME => 'username',
|
||||
) ), NULL, NULL, NULL, 'oauth_custom_auth_types' );
|
||||
$return['button_color'] = new \IPS\Helpers\Form\Color( 'oauth_custom_button_color', isset( $this->settings['button_color'] ) ? $this->settings['button_color'] : '#478F79', NULL, array(), NULL, NULL, NULL, 'button_color' );
|
||||
$return['button_text'] = new \IPS\Helpers\Form\Translatable( 'oauth_custom_button_text', NULL, NULL, array( 'placeholder' => \IPS\Member::loggedIn()->language()->addToStack('oauth_custom_button_text_custom_placeholder'), 'app' => 'core', 'key' => ( $this->id ? "core_custom_oauth_{$this->id}" : NULL ) ), NULL, NULL, NULL, 'button_text' );
|
||||
$return['button_icon'] = new \IPS\Helpers\Form\Upload( 'oauth_custom_button_icon', ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? \IPS\File::get( 'core_Login', $this->settings['button_icon'] ) : NULL, FALSE, array( 'storageExtension' => 'core_Login' ), NULL, NULL, NULL, 'button_icon' );
|
||||
$return['button_color'] = new Color( 'oauth_custom_button_color', $this->settings['button_color'] ?? '#478F79', NULL, array(), NULL, NULL, NULL, 'button_color' );
|
||||
$return['button_text'] = new Translatable( 'oauth_custom_button_text', NULL, NULL, array( 'placeholder' => Member::loggedIn()->language()->addToStack('oauth_custom_button_text_custom_placeholder'), 'app' => 'core', 'key' => ( $this->id ? "core_custom_oauth_{$this->id}" : NULL ) ), NULL, NULL, NULL, 'button_text' );
|
||||
$return['button_icon'] = new Upload( 'oauth_custom_button_icon', ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? File::get( 'core_Login', $this->settings['button_icon'] ) : NULL, FALSE, array( 'storageExtension' => 'core_Login' ), NULL, NULL, NULL, 'button_icon' );
|
||||
|
||||
$return[] = 'account_management_settings';
|
||||
foreach ( $accountManagementSettings as $k => $v )
|
||||
@@ -142,7 +167,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
* @param array $values Values from form
|
||||
* @return array
|
||||
*/
|
||||
public function acpFormSave( &$values )
|
||||
public function acpFormSave( array &$values ): array
|
||||
{
|
||||
$return = parent::acpFormSave( $values );
|
||||
$return['button_icon'] = (string) $return['button_icon'];
|
||||
@@ -158,7 +183,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
* @param array $values Values from the form
|
||||
* @return array
|
||||
*/
|
||||
public function formatFormValues( $values )
|
||||
public function formatFormValues( array $values ): array
|
||||
{
|
||||
$parent = parent::formatFormValues( $values );
|
||||
|
||||
@@ -168,7 +193,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
{
|
||||
$this->save();
|
||||
}
|
||||
\IPS\Lang::saveCustom( 'core', "core_custom_oauth_{$this->id}", $values['oauth_custom_button_text'] );
|
||||
Lang::saveCustom( 'core', "core_custom_oauth_{$this->id}", $values['oauth_custom_button_text'] );
|
||||
unset( $values['button_text'] );
|
||||
}
|
||||
|
||||
@@ -180,7 +205,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function buttonColor()
|
||||
public function buttonColor(): string
|
||||
{
|
||||
return $this->settings['button_color'];
|
||||
}
|
||||
@@ -190,28 +215,28 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function buttonIcon()
|
||||
public function buttonIcon(): string
|
||||
{
|
||||
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? \IPS\File::get( 'core_Login', $this->settings['button_icon'] ) : NULL;
|
||||
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? File::get( 'core_Login', $this->settings['button_icon'] ) : '';
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Get logo to display in information about logins with this method
|
||||
* Returns NULL for methods where it is not necessary to indicate the method, e..g Standard
|
||||
*
|
||||
* @return \IPS\Http\Url
|
||||
* @return Url|string|null
|
||||
*/
|
||||
public function logoForDeviceInformation()
|
||||
public function logoForDeviceInformation(): Url|string|null
|
||||
{
|
||||
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? \IPS\File::get( 'core_Login', $this->settings['button_icon'] )->url : NULL;
|
||||
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? File::get( 'core_Login', $this->settings['button_icon'] )->url : NULL;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Get logo to display in user cp sidebar
|
||||
*
|
||||
* @return \IPS\Http\Url
|
||||
* @return Url|string|null
|
||||
*/
|
||||
public function logoForUcp()
|
||||
public function logoForUcp(): Url|string|null
|
||||
{
|
||||
return $this->logoForDeviceInformation();
|
||||
}
|
||||
@@ -221,7 +246,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function buttonText()
|
||||
public function buttonText(): string
|
||||
{
|
||||
return "core_custom_oauth_{$this->id}";
|
||||
}
|
||||
@@ -231,9 +256,9 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
protected function grantType()
|
||||
protected function grantType(): string
|
||||
{
|
||||
return isset( $this->settings['grant_type'] ) ? $this->settings['grant_type'] : 'authorization_code';
|
||||
return $this->settings['grant_type'] ?? 'authorization_code';
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -241,18 +266,18 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
protected function _authenticationType()
|
||||
protected function _authenticationType(): string
|
||||
{
|
||||
return isset( $this->settings['authentication_type'] ) ? $this->settings['authentication_type'] : static::AUTHENTICATE_HEADER;
|
||||
return $this->settings['authentication_type'] ?? static::AUTHENTICATE_HEADER;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get scopes to request
|
||||
*
|
||||
* @param array|NULL $additional Any additional scopes to request
|
||||
* @param array|null $additional Any additional scopes to request
|
||||
* @return array
|
||||
*/
|
||||
protected function scopesToRequest( $additional=NULL )
|
||||
protected function scopesToRequest( array $additional=NULL ): array
|
||||
{
|
||||
return $this->settings['scopes'];
|
||||
}
|
||||
@@ -260,36 +285,36 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* Authorization Endpoint
|
||||
*
|
||||
* @param \IPS\Login $login The login object
|
||||
* @return \IPS\Http\Url
|
||||
* @param Login $login The login object
|
||||
* @return Url
|
||||
*/
|
||||
protected function authorizationEndpoint( \IPS\Login $login )
|
||||
protected function authorizationEndpoint( Login $login ): Url
|
||||
{
|
||||
if ( isset( $this->settings['authorization_endpoint_secure'] ) and $this->settings['authorization_endpoint_secure'] and ( $login->type === \IPS\Login::LOGIN_ACP or $login->type === \IPS\Login::LOGIN_REAUTHENTICATE ) )
|
||||
if ( isset( $this->settings['authorization_endpoint_secure'] ) and $this->settings['authorization_endpoint_secure'] and ( $login->type === Login::LOGIN_ACP or $login->type === Login::LOGIN_REAUTHENTICATE ) )
|
||||
{
|
||||
return \IPS\Http\Url::external( $this->settings['authorization_endpoint_secure'] );
|
||||
return Url::external( $this->settings['authorization_endpoint_secure'] );
|
||||
}
|
||||
|
||||
return \IPS\Http\Url::external( $this->settings['authorization_endpoint'] );
|
||||
return Url::external( $this->settings['authorization_endpoint'] );
|
||||
}
|
||||
|
||||
/**
|
||||
* Token Endpoint
|
||||
*
|
||||
* @return \IPS\Http\Url
|
||||
* @return Url
|
||||
*/
|
||||
protected function tokenEndpoint()
|
||||
protected function tokenEndpoint(): Url
|
||||
{
|
||||
return \IPS\Http\Url::external( $this->settings['token_endpoint'] );
|
||||
return Url::external( $this->settings['token_endpoint'] );
|
||||
}
|
||||
|
||||
/**
|
||||
* Get authenticated user's identifier (may not be a number)
|
||||
*
|
||||
* @param string $accessToken Access Token
|
||||
* @return string
|
||||
* @param string $accessToken Access Token
|
||||
* @return string|null
|
||||
*/
|
||||
protected function authenticatedUserId( $accessToken )
|
||||
protected function authenticatedUserId( string $accessToken ): ?string
|
||||
{
|
||||
if ( $userId = static::getValueFromArray( $this->_userData( $accessToken, $this->settings['uid_field'] ), $this->settings['uid_field'] ) )
|
||||
{
|
||||
@@ -305,7 +330,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
* @param string $accessToken Access Token
|
||||
* @return string|NULL
|
||||
*/
|
||||
protected function authenticatedUserName( $accessToken )
|
||||
protected function authenticatedUserName( string $accessToken ): ?string
|
||||
{
|
||||
if ( isset( $this->settings['name_field'] ) and $this->settings['name_field'] and $username = static::getValueFromArray( $this->_userData( $accessToken, $this->settings['name_field'] ), $this->settings['name_field'] ) )
|
||||
{
|
||||
@@ -321,7 +346,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
* @param string $accessToken Access Token
|
||||
* @return string|NULL
|
||||
*/
|
||||
protected function authenticatedEmail( $accessToken )
|
||||
protected function authenticatedEmail( string $accessToken ): ?string
|
||||
{
|
||||
if ( isset( $this->settings['email_field'] ) and $this->settings['email_field'] and $email = static::getValueFromArray( $this->_userData( $accessToken, $this->settings['email_field'] ), $this->settings['email_field'] ) )
|
||||
{
|
||||
@@ -334,24 +359,24 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
* Get user's profile photo
|
||||
* May return NULL if server doesn't support this
|
||||
*
|
||||
* @param \IPS\Member $member Member
|
||||
* @return \IPS\Http\Url|NULL
|
||||
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws \DomainException General error where it is safe to show a message to the user
|
||||
* @throws \RuntimeException Unexpected error from service
|
||||
* @param Member $member Member
|
||||
* @return Url|NULL
|
||||
* @throws Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws DomainException General error where it is safe to show a message to the user
|
||||
* @throws RuntimeException Unexpected error from service
|
||||
*/
|
||||
public function userProfilePhoto( \IPS\Member $member )
|
||||
public function userProfilePhoto( Member $member ): ?Url
|
||||
{
|
||||
if ( isset( $this->settings['photo_field'] ) and $this->settings['photo_field'] )
|
||||
{
|
||||
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
|
||||
{
|
||||
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
throw new Exception( "", Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
if ( $photo = static::getValueFromArray( $this->_userData( $link['token_access_token'], $this->settings['photo_field'] ), $this->settings['photo_field'] ) )
|
||||
{
|
||||
return \IPS\Http\Url::external( $photo );
|
||||
return Url::external( $photo );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -362,17 +387,17 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
* Get user's profile name
|
||||
* May return NULL if server doesn't support this
|
||||
*
|
||||
* @param \IPS\Member $member Member
|
||||
* @param Member $member Member
|
||||
* @return string|NULL
|
||||
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws \DomainException General error where it is safe to show a message to the user
|
||||
* @throws \RuntimeException Unexpected error from service
|
||||
* @throws Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws DomainException General error where it is safe to show a message to the user
|
||||
* @throws RuntimeException Unexpected error from service
|
||||
*/
|
||||
public function userProfileName( \IPS\Member $member )
|
||||
public function userProfileName( Member $member ): ?string
|
||||
{
|
||||
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
|
||||
{
|
||||
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
throw new Exception( "", Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
return $this->authenticatedUserName( $link['token_access_token'] );
|
||||
@@ -381,11 +406,11 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* Syncing Options
|
||||
*
|
||||
* @param \IPS\Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
|
||||
* @param Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
|
||||
* @param bool $defaultOnly If TRUE, only returns which options should be enabled by default for a new account
|
||||
* @return array
|
||||
*/
|
||||
public function syncOptions( \IPS\Member $member, $defaultOnly = FALSE )
|
||||
public function syncOptions( Member $member, bool $defaultOnly=FALSE ): array
|
||||
{
|
||||
$return = array();
|
||||
|
||||
@@ -410,21 +435,21 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* @brief Cached user data
|
||||
*/
|
||||
protected $_cachedUserData = array();
|
||||
|
||||
protected array $_cachedUserData = array();
|
||||
|
||||
/**
|
||||
* Get user data
|
||||
*
|
||||
* @param string $accessToken Access Token
|
||||
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws \RuntimeException Unexpected error from service
|
||||
* @param string $accessToken Access Token
|
||||
* @param string|null $expectedParam
|
||||
* @return array
|
||||
*/
|
||||
protected function _userData( $accessToken, $expectedParam = NULL )
|
||||
protected function _userData( string $accessToken, ?string $expectedParam = NULL ) : array
|
||||
{
|
||||
if ( !isset( $this->_cachedUserData[ $accessToken ] ) )
|
||||
{
|
||||
/* Try the most sensible way first */
|
||||
$response = \IPS\Http\Url::external( $this->settings['user_endpoint'] )->request()
|
||||
$response = Url::external( $this->settings['user_endpoint'] )->request()
|
||||
->setHeaders( array(
|
||||
'Authorization' => "Bearer {$accessToken}"
|
||||
) )
|
||||
@@ -437,7 +462,7 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
{
|
||||
if ( static::getValueFromArray( $response, $expectedParam ) === NULL )
|
||||
{
|
||||
$response = \IPS\Http\Url::external( $this->settings['user_endpoint'] )->setQueryString( 'access_token', $accessToken )->request()
|
||||
$response = Url::external( $this->settings['user_endpoint'] )->setQueryString( 'access_token', $accessToken )->request()
|
||||
->get()
|
||||
->decodeJson();
|
||||
}
|
||||
@@ -446,8 +471,8 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
/* Check for any errors */
|
||||
if ( $response === NULL OR static::getValueFromArray( $response, $this->settings['uid_field'] ) === NULL )
|
||||
{
|
||||
\IPS\Log::log( print_r( $response, TRUE ), 'oauth_custom' );
|
||||
throw new \IPS\Login\Exception( 'generic_error', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
Log::log( print_r( $response, TRUE ), 'oauth_custom' );
|
||||
throw new Exception( 'generic_error', Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
/* Set */
|
||||
@@ -459,11 +484,11 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* Get value from an array
|
||||
*
|
||||
* @param array $array The array with the data
|
||||
* @param string $key The key using[square][brackets]
|
||||
* @param array $array The array with the data
|
||||
* @param string $key The key using[square][brackets]
|
||||
* @return mixed
|
||||
*/
|
||||
protected static function getValueFromArray( $array, $key )
|
||||
protected static function getValueFromArray( array $array, string $key ): mixed
|
||||
{
|
||||
while ( $pos = mb_strpos( $key, '[' ) )
|
||||
{
|
||||
@@ -489,10 +514,10 @@ class _Custom extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* Forgot Password URL
|
||||
*
|
||||
* @return \IPS\Http\Url|NULL
|
||||
* @return Url|NULL
|
||||
*/
|
||||
public function forgotPasswordUrl()
|
||||
public function forgotPasswordUrl(): ?Url
|
||||
{
|
||||
return ( isset( $this->settings['forgot_password_url'] ) and $this->settings['forgot_password_url'] ) ? \IPS\Http\Url::external( $this->settings['forgot_password_url'] ) : NULL;
|
||||
return ( isset( $this->settings['forgot_password_url'] ) and $this->settings['forgot_password_url'] ) ? Url::external( $this->settings['forgot_password_url'] ) : NULL;
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user