Version 5.0.0 beta 1
This commit is contained in:
1 parent
25ddeb65d6
commit
15c7beabc5
6736 files changed
+627902
-497943
No files matched your search
@@ -11,28 +11,43 @@
|
||||
namespace IPS\Login\Handler\OAuth2;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
|
||||
use DomainException;
|
||||
use IPS\Db;
|
||||
use IPS\Helpers\Form\Radio;
|
||||
use IPS\Http\Url;
|
||||
use IPS\Login;
|
||||
use IPS\Login\Exception;
|
||||
use IPS\Login\Handler\OAuth2;
|
||||
use IPS\Member;
|
||||
use IPS\Theme;
|
||||
use RuntimeException;
|
||||
use UnderflowException;
|
||||
use function defined;
|
||||
use function in_array;
|
||||
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Google Login Handler
|
||||
*/
|
||||
class _Google extends \IPS\Login\Handler\OAuth2
|
||||
class Google extends OAuth2
|
||||
{
|
||||
/**
|
||||
* Get title
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public static function getTitle()
|
||||
public static function getTitle(): string
|
||||
{
|
||||
return 'login_handler_Google';
|
||||
}
|
||||
|
||||
protected static $enableAcpLoginByDefault = FALSE;
|
||||
protected static bool $enableAcpLoginByDefault = FALSE;
|
||||
|
||||
/**
|
||||
* ACP Settings Form
|
||||
@@ -42,14 +57,14 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
return array( 'savekey' => new \IPS\Helpers\Form\[Type]( ... ), ... );
|
||||
* @endcode
|
||||
*/
|
||||
public function acpForm()
|
||||
public function acpForm(): array
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words['login_acp_desc'] = \IPS\Member::loggedIn()->language()->addToStack('login_acp_cannot_reauth');
|
||||
\IPS\Member::loggedIn()->language()->words['oauth_client_id'] = \IPS\Member::loggedIn()->language()->addToStack('login_google_id');
|
||||
Member::loggedIn()->language()->words['login_acp_desc'] = Member::loggedIn()->language()->addToStack('login_acp_cannot_reauth');
|
||||
Member::loggedIn()->language()->words['oauth_client_id'] = Member::loggedIn()->language()->addToStack('login_google_id');
|
||||
|
||||
return array_merge(
|
||||
array(
|
||||
'real_name' => new \IPS\Helpers\Form\Radio( 'login_real_name', isset( $this->settings['real_name'] ) ? $this->settings['real_name'] : 1, FALSE, array(
|
||||
'real_name' => new Radio( 'login_real_name', $this->settings['real_name'] ?? 1, FALSE, array(
|
||||
'options' => array(
|
||||
1 => 'login_real_name_google',
|
||||
0 => 'login_real_name_disabled',
|
||||
@@ -68,7 +83,7 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function buttonColor()
|
||||
public function buttonColor(): string
|
||||
{
|
||||
return '#4285F4';
|
||||
}
|
||||
@@ -78,7 +93,7 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function buttonIcon()
|
||||
public function buttonIcon(): string
|
||||
{
|
||||
return 'google';
|
||||
}
|
||||
@@ -88,7 +103,7 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function buttonText()
|
||||
public function buttonText(): string
|
||||
{
|
||||
return 'login_google';
|
||||
}
|
||||
@@ -98,20 +113,20 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function buttonClass()
|
||||
public function buttonClass(): string
|
||||
{
|
||||
return 'ipsSocial_google';
|
||||
return 'ipsSocial--google';
|
||||
}
|
||||
|
||||
/**
|
||||
* Get logo to display in information about logins with this method
|
||||
* Returns NULL for methods where it is not necessary to indicate the method, e..g Standard
|
||||
*
|
||||
* @return \IPS\Http\Url
|
||||
* @return Url|string|null
|
||||
*/
|
||||
public function logoForDeviceInformation()
|
||||
public function logoForDeviceInformation(): Url|string|null
|
||||
{
|
||||
return \IPS\Theme::i()->resource( 'logos/login/Google.png', 'core', 'interface' );
|
||||
return Theme::i()->resource( 'logos/login/Google.png', 'core', 'interface' );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -119,7 +134,7 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
protected function grantType()
|
||||
protected function grantType(): string
|
||||
{
|
||||
return 'authorization_code';
|
||||
}
|
||||
@@ -130,27 +145,25 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
* @param array|NULL $additional Any additional scopes to request
|
||||
* @return array
|
||||
*/
|
||||
protected function scopesToRequest( $additional=NULL )
|
||||
protected function scopesToRequest( array $additional=NULL ): array
|
||||
{
|
||||
$return = array(
|
||||
return array(
|
||||
'profile',
|
||||
'email',
|
||||
);
|
||||
|
||||
return $return;
|
||||
}
|
||||
|
||||
/**
|
||||
* Scopes Issued
|
||||
*
|
||||
* @param string $accessToken Access Token
|
||||
* @param string $accessToken Access Token
|
||||
* @return array|NULL
|
||||
*/
|
||||
public function scopesIssued( $accessToken )
|
||||
public function scopesIssued( string $accessToken ): ?array
|
||||
{
|
||||
try
|
||||
{
|
||||
$response = \IPS\Http\Url::external( "https://www.googleapis.com/oauth2/v2/tokeninfo" )
|
||||
$response = Url::external( "https://www.googleapis.com/oauth2/v2/tokeninfo" )
|
||||
->setQueryString( 'access_token', $accessToken )
|
||||
->request()
|
||||
->get()
|
||||
@@ -167,25 +180,25 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* Authorization Endpoint
|
||||
*
|
||||
* @param \IPS\Login $login The login object
|
||||
* @return \IPS\Http\Url
|
||||
* @param Login $login The login object
|
||||
* @return Url
|
||||
*/
|
||||
protected function authorizationEndpoint( \IPS\Login $login )
|
||||
protected function authorizationEndpoint( Login $login ): Url
|
||||
{
|
||||
$return = \IPS\Http\Url::external('https://accounts.google.com/o/oauth2/v2/auth?access_type=offline');
|
||||
$return = Url::external('https://accounts.google.com/o/oauth2/v2/auth?access_type=offline');
|
||||
|
||||
if ( $login->type === \IPS\Login::LOGIN_ACP or $login->type === \IPS\Login::LOGIN_REAUTHENTICATE )
|
||||
if ( $login->type === Login::LOGIN_ACP or $login->type === Login::LOGIN_REAUTHENTICATE )
|
||||
{
|
||||
$return = $return->setQueryString( 'prompt', 'consent' );
|
||||
}
|
||||
|
||||
if ( $login->type === \IPS\Login::LOGIN_REAUTHENTICATE )
|
||||
if ( $login->type === Login::LOGIN_REAUTHENTICATE )
|
||||
{
|
||||
try
|
||||
{
|
||||
$return = $return->setQueryString( 'login_hint', $this->authenticatedEmail( \IPS\Db::i()->select( 'token_access_token', 'core_login_links', array( 'token_login_method=? AND token_member=?', $this->id, $login->reauthenticateAs->member_id ) )->first() ) );
|
||||
$return = $return->setQueryString( 'login_hint', $this->authenticatedEmail( Db::i()->select( 'token_access_token', 'core_login_links', array( 'token_login_method=? AND token_member=?', $this->id, $login->reauthenticateAs->member_id ) )->first() ) );
|
||||
}
|
||||
catch ( \UnderflowException $e ) {}
|
||||
catch ( UnderflowException $e ) {}
|
||||
}
|
||||
|
||||
return $return;
|
||||
@@ -194,34 +207,34 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* Token Endpoint
|
||||
*
|
||||
* @return \IPS\Http\Url
|
||||
* @return Url
|
||||
*/
|
||||
protected function tokenEndpoint()
|
||||
protected function tokenEndpoint(): Url
|
||||
{
|
||||
return \IPS\Http\Url::external('https://www.googleapis.com/oauth2/v4/token');
|
||||
return Url::external('https://www.googleapis.com/oauth2/v4/token');
|
||||
}
|
||||
|
||||
/**
|
||||
* Redirection Endpoint
|
||||
*
|
||||
* @return \IPS\Http\Url
|
||||
* @return Url
|
||||
*/
|
||||
protected function redirectionEndpoint()
|
||||
protected function redirectionEndpoint(): Url
|
||||
{
|
||||
if ( isset( $this->settings['legacy_redirect'] ) and $this->settings['legacy_redirect'] )
|
||||
{
|
||||
return \IPS\Http\Url::internal( 'applications/core/interface/google/auth.php', 'none' );
|
||||
return Url::internal( 'applications/core/interface/google/auth.php', 'none' );
|
||||
}
|
||||
return parent::redirectionEndpoint();
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Get authenticated user's identifier (may not be a number)
|
||||
*
|
||||
* @param string $accessToken Access Token
|
||||
* @return string
|
||||
* @param string $accessToken Access Token
|
||||
* @return string|null
|
||||
*/
|
||||
protected function authenticatedUserId( $accessToken )
|
||||
protected function authenticatedUserId( string $accessToken ): ?string
|
||||
{
|
||||
return $this->_userData( $accessToken )['sub'];
|
||||
}
|
||||
@@ -233,7 +246,7 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
* @param string $accessToken Access Token
|
||||
* @return string|NULL
|
||||
*/
|
||||
protected function authenticatedUserName( $accessToken )
|
||||
protected function authenticatedUserName( string $accessToken ): ?string
|
||||
{
|
||||
if ( isset( $this->settings['real_name'] ) and $this->settings['real_name'] )
|
||||
{
|
||||
@@ -249,7 +262,7 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
* @param string $accessToken Access Token
|
||||
* @return string|NULL
|
||||
*/
|
||||
protected function authenticatedEmail( $accessToken )
|
||||
protected function authenticatedEmail( string $accessToken ): ?string
|
||||
{
|
||||
return $this->_userData( $accessToken )['email'];
|
||||
}
|
||||
@@ -258,23 +271,23 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
* Get user's profile photo
|
||||
* May return NULL if server doesn't support this
|
||||
*
|
||||
* @param \IPS\Member $member Member
|
||||
* @return \IPS\Http\Url|NULL
|
||||
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws \DomainException General error where it is safe to show a message to the user
|
||||
* @throws \RuntimeException Unexpected error from service
|
||||
* @param Member $member Member
|
||||
* @return Url|NULL
|
||||
* @throws Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws DomainException General error where it is safe to show a message to the user
|
||||
* @throws RuntimeException Unexpected error from service
|
||||
*/
|
||||
public function userProfilePhoto( \IPS\Member $member )
|
||||
public function userProfilePhoto( Member $member ): ?Url
|
||||
{
|
||||
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
|
||||
{
|
||||
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
throw new Exception( "", Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
$userData = $this->_userData( $link['token_access_token'] );
|
||||
if ( isset( $userData['picture'] ) and $userData['picture'] )
|
||||
{
|
||||
return \IPS\Http\Url::external( $userData['picture'] )->setQueryString( 'sz', NULL );
|
||||
return Url::external( $userData['picture'] )->setQueryString( 'sz', NULL );
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
@@ -283,17 +296,17 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
* Get user's profile name
|
||||
* May return NULL if server doesn't support this
|
||||
*
|
||||
* @param \IPS\Member $member Member
|
||||
* @param Member $member Member
|
||||
* @return string|NULL
|
||||
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws \DomainException General error where it is safe to show a message to the user
|
||||
* @throws \RuntimeException Unexpected error from service
|
||||
* @throws Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws DomainException General error where it is safe to show a message to the user
|
||||
* @throws RuntimeException Unexpected error from service
|
||||
*/
|
||||
public function userProfileName( \IPS\Member $member )
|
||||
public function userProfileName( Member $member ): ?string
|
||||
{
|
||||
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
|
||||
{
|
||||
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
throw new Exception( "", Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
return $this->_userData( $link['token_access_token'] )['name'];
|
||||
@@ -305,12 +318,12 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
*
|
||||
* @param string $identifier The ID Nnumber/string from remote service
|
||||
* @param string $username The username from remote service
|
||||
* @return \IPS\Http\Url|NULL
|
||||
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws \DomainException General error where it is safe to show a message to the user
|
||||
* @throws \RuntimeException Unexpected error from service
|
||||
* @return Url|NULL
|
||||
* @throws Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws DomainException General error where it is safe to show a message to the user
|
||||
* @throws RuntimeException Unexpected error from service
|
||||
*/
|
||||
public function userLink( $identifier, $username )
|
||||
public function userLink( string $identifier, string $username ): ?Url
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
@@ -318,11 +331,11 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* Syncing Options
|
||||
*
|
||||
* @param \IPS\Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
|
||||
* @param Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
|
||||
* @param bool $defaultOnly If TRUE, only returns which options should be enabled by default for a new account
|
||||
* @return array
|
||||
*/
|
||||
public function syncOptions( \IPS\Member $member, $defaultOnly = FALSE )
|
||||
public function syncOptions( Member $member, bool $defaultOnly=FALSE ): array
|
||||
{
|
||||
$authorizedScopes = $this->authorizedScopes( $member );
|
||||
|
||||
@@ -333,7 +346,7 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
|
||||
$return = array();
|
||||
|
||||
if ( ( !isset( $this->settings['update_email_changes'] ) or $this->settings['update_email_changes'] === 'optional' ) and ( \in_array( 'email', $authorizedScopes ) or \in_array( 'https://www.googleapis.com/auth/userinfo.email', $authorizedScopes ) ) )
|
||||
if ( ( !isset( $this->settings['update_email_changes'] ) or $this->settings['update_email_changes'] === 'optional' ) and ( in_array( 'email', $authorizedScopes ) or in_array( 'https://www.googleapis.com/auth/userinfo.email', $authorizedScopes ) ) )
|
||||
{
|
||||
$return[] = 'email';
|
||||
}
|
||||
@@ -351,20 +364,20 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
/**
|
||||
* @brief Cached user data
|
||||
*/
|
||||
protected $_cachedUserData = array();
|
||||
protected array $_cachedUserData = array();
|
||||
|
||||
/**
|
||||
* Get user data
|
||||
*
|
||||
* @param string $accessToken Access Token
|
||||
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws \RuntimeException Unexpected error from service
|
||||
* @throws Exception The token is invalid and the user needs to reauthenticate
|
||||
* @throws RuntimeException Unexpected error from service
|
||||
*/
|
||||
protected function _userData( $accessToken )
|
||||
protected function _userData( string $accessToken ): array
|
||||
{
|
||||
if ( !isset( $this->_cachedUserData[ $accessToken ] ) )
|
||||
{
|
||||
$response = \IPS\Http\Url::external( "https://www.googleapis.com/oauth2/v3/userinfo" )
|
||||
$response = Url::external( "https://www.googleapis.com/oauth2/v3/userinfo" )
|
||||
->request()
|
||||
->setHeaders( array(
|
||||
'Authorization' => "Bearer {$accessToken}"
|
||||
@@ -376,12 +389,12 @@ class _Google extends \IPS\Login\Handler\OAuth2
|
||||
{
|
||||
if ( isset( $response['error_description'] ) )
|
||||
{
|
||||
throw new \IPS\Login\Exception( $response['error_description'], \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
throw new Exception( $response['error_description'], Exception::INTERNAL_ERROR );
|
||||
}
|
||||
// Keeping this for backwards compatibility..
|
||||
else if( isset( $response['error']['errors'][0]['message'] ) )
|
||||
{
|
||||
throw new \IPS\Login\Exception( $response['error']['errors'][0]['message'], \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
throw new Exception( $response['error']['errors'][0]['message'], Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user