Version 5.0.0 beta 1

This commit is contained in:
Neo committed 2025-12-19 16:27:35 -08:00
1 parent 25ddeb65d6
commit 15c7beabc5
6736 files changed
+627902 -497943

No files matched your search

+114 -93
View File
@@ -11,28 +11,49 @@
namespace IPS\Login\Handler\OAuth2;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use DomainException;
use Exception;
use IPS\File;
use IPS\Helpers\Form\Color;
use IPS\Helpers\Form\Radio;
use IPS\Helpers\Form\Select;
use IPS\Helpers\Form\Translatable;
use IPS\Helpers\Form\Upload;
use IPS\Http\Url;
use IPS\Lang;
use IPS\Login;
use IPS\Login\Exception as LoginException;
use IPS\Login\Handler\OAuth2;
use IPS\Member;
use IPS\Settings;
use RuntimeException;
use function defined;
use function is_array;
use function is_string;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* Invision Community Login Handler
*/
class _Invision extends \IPS\Login\Handler\OAuth2
class Invision extends OAuth2
{
/**
* @brief Can we have multiple instances of this handler?
*/
public static $allowMultiple = TRUE;
public static bool $allowMultiple = TRUE;
/**
* Get title
*
* @return string
*/
public static function getTitle()
public static function getTitle(): string
{
return 'login_handler_InvisionCommunity';
}
@@ -45,21 +66,21 @@ class _Invision extends \IPS\Login\Handler\OAuth2
return array( 'savekey' => new \IPS\Helpers\Form\[Type]( ... ), ... );
* @endcode
*/
public function acpForm()
public function acpForm(): array
{
\IPS\Member::loggedIn()->language()->words['login_acp_desc'] = \IPS\Member::loggedIn()->language()->addToStack('login_acp_will_reauth');
Member::loggedIn()->language()->words['login_acp_desc'] = Member::loggedIn()->language()->addToStack('login_acp_will_reauth');
$return = array();
$return[] = array( 'login_handler_InvisionCommunity_info_title', 'login_handler_InvisionCommunity_info' );
$return['url'] = new \IPS\Helpers\Form\Url( 'oauth_invision_endpoint', isset( $this->settings['url'] ) ? $this->settings['url'] : NULL, TRUE, array( 'placeholder' => 'https://othercommunity.example.com' ), function( $val )
$return['url'] = new \IPS\Helpers\Form\Url( 'oauth_invision_endpoint', $this->settings['url'] ?? NULL, TRUE, array( 'placeholder' => 'https://othercommunity.example.com' ), function( $val )
{
if ( rtrim( (string) $val, '/' ) === rtrim( \IPS\Settings::i()->base_url, '/' ) )
if ( rtrim( (string) $val, '/' ) === rtrim( Settings::i()->base_url, '/' ) )
{
throw new \DomainException('oauth_invision_endpoint_internal');
throw new DomainException('oauth_invision_endpoint_internal');
}
} );
$return['grant_type'] = new \IPS\Helpers\Form\Radio( 'oauth_invision_grant_type', isset( $this->settings['grant_type'] ) ? $this->settings['grant_type'] : 'authorization_code', TRUE, array(
$return['grant_type'] = new Radio( 'oauth_invision_grant_type', $this->settings['grant_type'] ?? 'authorization_code', TRUE, array(
'options' => array(
'authorization_code' => 'invision_grant_type_authorization_code',
'password' => 'invision_grant_type_password',
@@ -77,21 +98,21 @@ class _Invision extends \IPS\Login\Handler\OAuth2
{
$active = 'accountManagementSettings';
}
if ( !\is_string( $v ) and !\is_array( $v ) )
if ( !is_string( $v ) and !is_array( $v ) )
{
${$active}[ $k ] = $v;
}
}
$return[] = 'login_handler_oauth_ui';
$return['auth_types'] = new \IPS\Helpers\Form\Select( 'oauth_custom_auth_types', isset( $this->settings['auth_types'] ) ? $this->settings['auth_types'] : ( \IPS\Login::AUTH_TYPE_USERNAME + \IPS\Login::AUTH_TYPE_EMAIL ), TRUE, array( 'options' => array(
\IPS\Login::AUTH_TYPE_USERNAME + \IPS\Login::AUTH_TYPE_EMAIL => 'username_or_email',
\IPS\Login::AUTH_TYPE_EMAIL => 'email_address',
\IPS\Login::AUTH_TYPE_USERNAME => 'username',
$return['auth_types'] = new Select( 'oauth_custom_auth_types', $this->settings['auth_types'] ?? ( Login::AUTH_TYPE_USERNAME + Login::AUTH_TYPE_EMAIL ), TRUE, array( 'options' => array(
Login::AUTH_TYPE_USERNAME + Login::AUTH_TYPE_EMAIL => 'username_or_email',
Login::AUTH_TYPE_EMAIL => 'email_address',
Login::AUTH_TYPE_USERNAME => 'username',
) ), NULL, NULL, NULL, 'oauth_custom_auth_types' );
$return['button_color'] = new \IPS\Helpers\Form\Color( 'oauth_custom_button_color', isset( $this->settings['button_color'] ) ? $this->settings['button_color'] : '#3E4148', NULL, array(), NULL, NULL, NULL, 'button_color' );
$return['button_text'] = new \IPS\Helpers\Form\Translatable( 'oauth_custom_button_text', NULL, NULL, array( 'placeholder' => \IPS\Member::loggedIn()->language()->addToStack('oauth_custom_button_text_invision_placeholder'), 'app' => 'core', 'key' => ( $this->id ? "core_custom_oauth_{$this->id}" : NULL ) ), NULL, NULL, NULL, 'button_text' );
$return['button_icon'] = new \IPS\Helpers\Form\Upload( 'oauth_custom_button_icon', ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? \IPS\File::get( 'core_Login', $this->settings['button_icon'] ) : NULL, FALSE, array( 'storageExtension' => 'core_Login' ), NULL, NULL, NULL, 'button_icon' );
$return['button_color'] = new Color( 'oauth_custom_button_color', $this->settings['button_color'] ?? '#3E4148', NULL, array(), NULL, NULL, NULL, 'button_color' );
$return['button_text'] = new Translatable( 'oauth_custom_button_text', NULL, NULL, array( 'placeholder' => Member::loggedIn()->language()->addToStack('oauth_custom_button_text_invision_placeholder'), 'app' => 'core', 'key' => ( $this->id ? "core_custom_oauth_{$this->id}" : NULL ) ), NULL, NULL, NULL, 'button_text' );
$return['button_icon'] = new Upload( 'oauth_custom_button_icon', ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? File::get( 'core_Login', $this->settings['button_icon'] ) : NULL, FALSE, array( 'storageExtension' => 'core_Login' ), NULL, NULL, NULL, 'button_icon' );
$return[] = 'account_management_settings';
foreach ( $accountManagementSettings as $k => $v )
@@ -108,7 +129,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* @param array $values Values from form
* @return array
*/
public function acpFormSave( &$values )
public function acpFormSave( array &$values ): array
{
$return = parent::acpFormSave( $values );
$return['url'] = (string) $return['url'];
@@ -122,7 +143,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* @param array $values Values from the form
* @return array
*/
public function formatFormValues( $values )
public function formatFormValues( array $values ): array
{
if( isset( $values['oauth_custom_button_text'] ) )
{
@@ -130,7 +151,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
{
$this->save();
}
\IPS\Lang::saveCustom( 'core', "core_custom_oauth_{$this->id}", $values['oauth_custom_button_text'] );
Lang::saveCustom( 'core', "core_custom_oauth_{$this->id}", $values['oauth_custom_button_text'] );
unset( $values['button_text'] );
}
@@ -142,7 +163,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonColor()
public function buttonColor(): string
{
return $this->settings['button_color'];
}
@@ -152,9 +173,9 @@ class _Invision extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonIcon()
public function buttonIcon(): string
{
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? \IPS\File::get( 'core_Login', $this->settings['button_icon'] ) : NULL;
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? File::get( 'core_Login', $this->settings['button_icon'] ) : '';
}
/**
@@ -162,28 +183,28 @@ class _Invision extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonClass()
public function buttonClass(): string
{
return 'ipsSocial_ips';
return 'ipsSocial--ips';
}
/**
* Get logo to display in information about logins with this method
* Returns NULL for methods where it is not necessary to indicate the method, e..g Standard
*
* @return \IPS\Http\Url
* @return Url|string|null
*/
public function logoForDeviceInformation()
public function logoForDeviceInformation(): Url|string|null
{
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? \IPS\File::get( 'core_Login', $this->settings['button_icon'] )->url : NULL;
return ( isset( $this->settings['button_icon'] ) and $this->settings['button_icon'] ) ? File::get( 'core_Login', $this->settings['button_icon'] )->url : NULL;
}
/**
* Get logo to display in user cp sidebar
*
* @return \IPS\Http\Url
* @return Url|string|null
*/
public function logoForUcp()
public function logoForUcp(): Url|string|null
{
return $this->logoForDeviceInformation();
}
@@ -193,7 +214,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonText()
public function buttonText(): string
{
return "core_custom_oauth_{$this->id}";
}
@@ -203,7 +224,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
protected function _authenticationType()
protected function _authenticationType(): string
{
return static::AUTHENTICATE_POST; // Just because it's possible their server isn't configured to accept HTTP Authorization whereas we know this will always work
}
@@ -213,9 +234,9 @@ class _Invision extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
protected function grantType()
protected function grantType(): string
{
return isset( $this->settings['grant_type'] ) ? $this->settings['grant_type'] : 'authorization_code';
return $this->settings['grant_type'] ?? 'authorization_code';
}
/**
@@ -224,7 +245,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* @param array|NULL $additional Any additional scopes to request
* @return array
*/
protected function scopesToRequest( $additional=NULL )
protected function scopesToRequest( array $additional=NULL ): array
{
return array( 'profile', 'email' );
}
@@ -232,14 +253,14 @@ class _Invision extends \IPS\Login\Handler\OAuth2
/**
* Authorization Endpoint
*
* @param \IPS\Login $login The login object
* @return \IPS\Http\Url
* @param Login $login The login object
* @return Url
*/
protected function authorizationEndpoint( \IPS\Login $login )
protected function authorizationEndpoint( Login $login ): Url
{
$return = \IPS\Http\Url::external( $this->settings['url'] . '/oauth/authorize/' );
$return = Url::external( $this->settings['url'] . '/oauth/authorize/' );
if ( $login->type === \IPS\Login::LOGIN_ACP or $login->type === \IPS\Login::LOGIN_REAUTHENTICATE )
if ( $login->type === Login::LOGIN_ACP or $login->type === Login::LOGIN_REAUTHENTICATE )
{
$return = $return->setQueryString( 'prompt', 'login' );
}
@@ -250,20 +271,20 @@ class _Invision extends \IPS\Login\Handler\OAuth2
/**
* Token Endpoint
*
* @return \IPS\Http\Url
* @return Url
*/
protected function tokenEndpoint()
protected function tokenEndpoint(): Url
{
return \IPS\Http\Url::external( $this->settings['url'] . '/oauth/token/' );
return Url::external( $this->settings['url'] . '/oauth/token/' );
}
/**
* Get authenticated user's identifier (may not be a number)
*
* @param string $accessToken Access Token
* @return string
* @return string|null
*/
protected function authenticatedUserId( $accessToken )
protected function authenticatedUserId( string $accessToken ): ?string
{
$userData = $this->_userData( $accessToken );
if ( isset( $userData['id'] ) )
@@ -280,7 +301,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* @param string $accessToken Access Token
* @return string|NULL
*/
protected function authenticatedUserName( $accessToken )
protected function authenticatedUserName( string $accessToken ): ?string
{
$userData = $this->_userData( $accessToken );
if ( isset( $userData['name'] ) )
@@ -297,7 +318,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* @param string $accessToken Access Token
* @return string|NULL
*/
protected function authenticatedEmail( $accessToken )
protected function authenticatedEmail( string $accessToken ): ?string
{
$userData = $this->_userData( $accessToken );
if ( isset( $userData['email'] ) )
@@ -311,23 +332,23 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* Get user's profile photo
* May return NULL if server doesn't support this
*
* @param \IPS\Member $member Member
* @return \IPS\Http\Url|NULL
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
* @throws \DomainException General error where it is safe to show a message to the user
* @throws \RuntimeException Unexpected error from service
* @param Member $member Member
* @return Url|NULL
* @throws LoginException The token is invalid and the user needs to reauthenticate
* @throws DomainException General error where it is safe to show a message to the user
* @throws RuntimeException Unexpected error from service
*/
public function userProfilePhoto( \IPS\Member $member )
public function userProfilePhoto( Member $member ): ?Url
{
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
{
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
throw new LoginException( "", LoginException::INTERNAL_ERROR );
}
$userData = $this->_userData( $link['token_access_token'] );
if ( ( !isset( $userData['photoUrlIsDefault'] ) or !$userData['photoUrlIsDefault'] ) AND isset( $userData['photoUrl'] ) )
{
return \IPS\Http\Url::external( $userData['photoUrl'] );
return Url::external( $userData['photoUrl'] );
}
return NULL;
}
@@ -336,17 +357,17 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* Get user's profile name
* May return NULL if server doesn't support this
*
* @param \IPS\Member $member Member
* @param Member $member Member
* @return string|NULL
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
* @throws \DomainException General error where it is safe to show a message to the user
* @throws \RuntimeException Unexpected error from service
* @throws LoginException The token is invalid and the user needs to reauthenticate
* @throws DomainException General error where it is safe to show a message to the user
* @throws RuntimeException Unexpected error from service
*/
public function userProfileName( \IPS\Member $member )
public function userProfileName( Member $member ): ?string
{
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
{
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
throw new LoginException( "", LoginException::INTERNAL_ERROR );
}
$userData = $this->_userData( $link['token_access_token'] );
@@ -362,23 +383,23 @@ class _Invision extends \IPS\Login\Handler\OAuth2
* Get user's cover photo
* May return NULL if server doesn't support this
*
* @param \IPS\Member $member Member
* @return \IPS\Http\Url|NULL
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
* @throws \DomainException General error where it is safe to show a message to the user
* @throws \RuntimeException Unexpected error from service
* @param Member $member Member
* @return Url|NULL
* @throws LoginException The token is invalid and the user needs to reauthenticate
* @throws DomainException General error where it is safe to show a message to the user
* @throws RuntimeException Unexpected error from service
*/
public function userCoverPhoto( \IPS\Member $member )
public function userCoverPhoto( Member $member ): ?Url
{
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
{
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
throw new LoginException( "", LoginException::INTERNAL_ERROR );
}
$userData = $this->_userData( $link['token_access_token'] );
if ( isset( $userData['coverPhotoUrl'] ) and $userData['coverPhotoUrl'] )
{
return \IPS\Http\Url::external( $userData['coverPhotoUrl'] );
return Url::external( $userData['coverPhotoUrl'] );
}
return NULL;
@@ -390,24 +411,24 @@ class _Invision extends \IPS\Login\Handler\OAuth2
*
* @param string $identifier The ID Nnumber/string from remote service
* @param string $username The username from remote service
* @return \IPS\Http\Url|NULL
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
* @throws \DomainException General error where it is safe to show a message to the user
* @throws \RuntimeException Unexpected error from service
* @return Url|NULL
* @throws LoginException The token is invalid and the user needs to reauthenticate
* @throws DomainException General error where it is safe to show a message to the user
* @throws RuntimeException Unexpected error from service
*/
public function userLink( $identifier, $username )
public function userLink( string $identifier, string $username ): ?Url
{
return \IPS\Http\Url::external( $this->settings['url'] )->setQueryString( 'showuser', $identifier );
return Url::external( $this->settings['url'] )->setQueryString( 'showuser', $identifier );
}
/**
* Syncing Options
*
* @param \IPS\Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
* @param Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
* @param bool $defaultOnly If TRUE, only returns which options should be enabled by default for a new account
* @return array
*/
public function syncOptions( \IPS\Member $member, $defaultOnly = FALSE )
public function syncOptions( Member $member, bool $defaultOnly=FALSE ): array
{
$return = array();
@@ -430,21 +451,21 @@ class _Invision extends \IPS\Login\Handler\OAuth2
/**
* @brief Cached user data
*/
protected $_cachedUserData = array();
protected array $_cachedUserData = array();
/**
* Get user data
*
* @param string $accessToken Access Token
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
* @throws \RuntimeException Unexpected error from service
* @return array|null
* @return array
*@throws RuntimeException Unexpected error from service
* @throws LoginException The token is invalid and the user needs to reauthenticate
*/
protected function _userData( $accessToken )
protected function _userData( string $accessToken ): array
{
if ( !isset( $this->_cachedUserData[ $accessToken ] ) )
{
$response = \IPS\Http\Url::external( $this->settings['url'] . '/api/index.php?/core/me' )
$response = Url::external( $this->settings['url'] . '/api/index.php?/core/me' )
->request()
->setHeaders( array(
'Authorization' => "Bearer {$accessToken}"
@@ -454,12 +475,12 @@ class _Invision extends \IPS\Login\Handler\OAuth2
if ( isset( $response['errorCode'] ) )
{
throw new \IPS\Login\Exception( $response['errorMessage'], \IPS\Login\Exception::INTERNAL_ERROR );
throw new LoginException( $response['errorMessage'], LoginException::INTERNAL_ERROR );
}
try
{
$email = \IPS\Http\Url::external( $this->settings['url'] . '/api/index.php?/core/me/email' )
$email = Url::external( $this->settings['url'] . '/api/index.php?/core/me/email' )
->request()
->setHeaders( array(
'Authorization' => "Bearer {$accessToken}"
@@ -472,7 +493,7 @@ class _Invision extends \IPS\Login\Handler\OAuth2
$response['email'] = $email['email'];
}
}
catch ( \Exception $e ) { }
catch ( Exception $e ) { }
$this->_cachedUserData[ $accessToken ] = $response;
}
@@ -482,10 +503,10 @@ class _Invision extends \IPS\Login\Handler\OAuth2
/**
* Forgot Password URL
*
* @return \IPS\Http\Url|NULL
* @return Url|NULL
*/
public function forgotPasswordUrl()
public function forgotPasswordUrl(): ?Url
{
return \IPS\Http\Url::external( $this->settings['url'] . '/index.php?app=core&module=system&controller=lostpass' );
return Url::external( $this->settings['url'] . '/index.php?app=core&module=system&controller=lostpass' );
}
}