Version 5.0.0 beta 1

This commit is contained in:
Neo committed 2025-12-19 16:27:35 -08:00
1 parent 25ddeb65d6
commit 15c7beabc5
6736 files changed
+627902 -497943

No files matched your search

+62 -50
View File
@@ -11,28 +11,40 @@
namespace IPS\Login\Handler\OAuth2;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use DomainException;
use IPS\Helpers\Form\Radio;
use IPS\Http\Url;
use IPS\Login;
use IPS\Login\Exception;
use IPS\Login\Handler\OAuth2;
use IPS\Member;
use IPS\Theme;
use RuntimeException;
use function defined;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* Microsoft Login Handler
*/
class _Microsoft extends \IPS\Login\Handler\OAuth2
class Microsoft extends OAuth2
{
/**
* Get title
*
* @return string
*/
public static function getTitle()
public static function getTitle(): string
{
return 'login_handler_Live';
}
protected static $enableAcpLoginByDefault = FALSE;
protected static bool $enableAcpLoginByDefault = FALSE;
/**
* ACP Settings Form
@@ -42,14 +54,14 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
return array( 'savekey' => new \IPS\Helpers\Form\[Type]( ... ), ... );
* @endcode
*/
public function acpForm()
public function acpForm(): array
{
\IPS\Member::loggedIn()->language()->words['login_acp_desc'] = \IPS\Member::loggedIn()->language()->addToStack('login_acp_cannot_reauth');
\IPS\Member::loggedIn()->language()->words['oauth_client_id'] = \IPS\Member::loggedIn()->language()->addToStack('login_live_client');
\IPS\Member::loggedIn()->language()->words['oauth_client_client_secret'] = \IPS\Member::loggedIn()->language()->addToStack('login_live_secret');
Member::loggedIn()->language()->words['login_acp_desc'] = Member::loggedIn()->language()->addToStack('login_acp_cannot_reauth');
Member::loggedIn()->language()->words['oauth_client_id'] = Member::loggedIn()->language()->addToStack('login_live_client');
Member::loggedIn()->language()->words['oauth_client_client_secret'] = Member::loggedIn()->language()->addToStack('login_live_secret');
return array_merge( array(
'real_name' => new \IPS\Helpers\Form\Radio( 'login_real_name', isset( $this->settings['real_name'] ) ? $this->settings['real_name'] : 1, FALSE, array(
'real_name' => new Radio( 'login_real_name', $this->settings['real_name'] ?? 1, FALSE, array(
'options' => array(
1 => 'login_real_name_microsoft',
0 => 'login_real_name_disabled',
@@ -66,7 +78,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonColor()
public function buttonColor(): string
{
return '#008b00';
}
@@ -76,7 +88,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonIcon()
public function buttonIcon(): string
{
return 'windows';
}
@@ -86,7 +98,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonText()
public function buttonText(): string
{
return 'login_live';
}
@@ -96,20 +108,20 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
public function buttonClass()
public function buttonClass(): string
{
return 'ipsSocial_microsoft';
return 'ipsSocial--microsoft';
}
/**
* Get logo to display in information about logins with this method
* Returns NULL for methods where it is not necessary to indicate the method, e..g Standard
*
* @return \IPS\Http\Url
* @return Url|string|null
*/
public function logoForDeviceInformation()
public function logoForDeviceInformation(): Url|string|null
{
return \IPS\Theme::i()->resource( 'logos/login/Microsoft.png', 'core', 'interface' );
return Theme::i()->resource( 'logos/login/Microsoft.png', 'core', 'interface' );
}
/**
@@ -117,7 +129,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
*
* @return string
*/
protected function grantType()
protected function grantType(): string
{
return 'authorization_code';
}
@@ -128,7 +140,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
* @param array|NULL $additional Any additional scopes to request
* @return array
*/
protected function scopesToRequest( $additional=NULL )
protected function scopesToRequest( array $additional=NULL ): array
{
return array(
'openid',
@@ -140,45 +152,45 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
/**
* Authorization Endpoint
*
* @param \IPS\Login $login The login object
* @return \IPS\Http\Url
* @param Login $login The login object
* @return Url
*/
protected function authorizationEndpoint( \IPS\Login $login )
protected function authorizationEndpoint( Login $login ): Url
{
return \IPS\Http\Url::external('https://login.microsoftonline.com/common/oauth2/v2.0/authorize');
return Url::external('https://login.microsoftonline.com/common/oauth2/v2.0/authorize');
}
/**
* Token Endpoint
*
* @return \IPS\Http\Url
* @return Url
*/
protected function tokenEndpoint()
protected function tokenEndpoint(): Url
{
return \IPS\Http\Url::external('https://login.microsoftonline.com/common/oauth2/v2.0/token');
return Url::external('https://login.microsoftonline.com/common/oauth2/v2.0/token');
}
/**
* Redirection Endpoint
*
* @return \IPS\Http\Url
* @return Url
*/
protected function redirectionEndpoint()
protected function redirectionEndpoint(): Url
{
if ( isset( $this->settings['legacy_redirect'] ) and $this->settings['legacy_redirect'] )
{
return \IPS\Http\Url::internal( 'applications/core/interface/microsoft/auth.php', 'none' );
return Url::internal( 'applications/core/interface/microsoft/auth.php', 'none' );
}
return parent::redirectionEndpoint();
}
/**
* Get authenticated user's identifier (may not be a number)
*
* @param string $accessToken Access Token
* @return string
* @param string $accessToken Access Token
* @return string|null
*/
protected function authenticatedUserId( $accessToken )
protected function authenticatedUserId( string $accessToken ): ?string
{
return $this->_userData( $accessToken )['id'];
}
@@ -190,7 +202,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
* @param string $accessToken Access Token
* @return string|NULL
*/
protected function authenticatedUserName( $accessToken )
protected function authenticatedUserName( string $accessToken ): ?string
{
if ( isset( $this->settings['real_name'] ) and $this->settings['real_name'] )
{
@@ -206,7 +218,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
* @param string $accessToken Access Token
* @return string|NULL
*/
protected function authenticatedEmail( $accessToken )
protected function authenticatedEmail( string $accessToken ): ?string
{
return $this->_userData( $accessToken )['userPrincipalName'];
}
@@ -215,17 +227,17 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
* Get user's profile name
* May return NULL if server doesn't support this
*
* @param \IPS\Member $member Member
* @param Member $member Member
* @return string|NULL
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
* @throws \DomainException General error where it is safe to show a message to the user
* @throws \RuntimeException Unexpected error from service
* @throws Exception The token is invalid and the user needs to reauthenticate
* @throws DomainException General error where it is safe to show a message to the user
* @throws RuntimeException Unexpected error from service
*/
public function userProfileName( \IPS\Member $member )
public function userProfileName( Member $member ): ?string
{
if ( !( $link = $this->_link( $member ) ) or ( $link['token_expires'] and $link['token_expires'] < time() ) )
{
throw new \IPS\Login\Exception( NULL, \IPS\Login\Exception::INTERNAL_ERROR );
throw new Exception( "", Exception::INTERNAL_ERROR );
}
return $this->_userData( $link['token_access_token'] )['displayName'];
@@ -234,11 +246,11 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
/**
* Syncing Options
*
* @param \IPS\Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
* @param Member $member The member we're asking for (can be used to not show certain options iof the user didn't grant those scopes)
* @param bool $defaultOnly If TRUE, only returns which options should be enabled by default for a new account
* @return array
*/
public function syncOptions( \IPS\Member $member, $defaultOnly = FALSE )
public function syncOptions( Member $member, bool $defaultOnly=FALSE ): array
{
$return = array();
@@ -258,20 +270,20 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
/**
* @brief Cached user data
*/
protected $_cachedUserData = array();
protected array $_cachedUserData = array();
/**
* Get user data
*
* @param string $accessToken Access Token
* @throws \IPS\Login\Exception The token is invalid and the user needs to reauthenticate
* @throws \RuntimeException Unexpected error from service
* @throws Exception The token is invalid and the user needs to reauthenticate
* @throws RuntimeException Unexpected error from service
*/
protected function _userData( $accessToken )
protected function _userData( string $accessToken ): array
{
if ( !isset( $this->_cachedUserData[ $accessToken ] ) )
{
$response = \IPS\Http\Url::external( "https://graph.microsoft.com/v1.0/me" )
$response = Url::external( "https://graph.microsoft.com/v1.0/me" )
->request()
->setHeaders( array(
'Authorization' => "Bearer {$accessToken}"
@@ -281,7 +293,7 @@ class _Microsoft extends \IPS\Login\Handler\OAuth2
if ( isset( $response['error'] ) )
{
throw new \IPS\Login\Exception( $response['error']['message'], \IPS\Login\Exception::INTERNAL_ERROR );
throw new Exception( $response['error']['message'], Exception::INTERNAL_ERROR );
}
$this->_cachedUserData[ $accessToken ] = $response;