Version 4.5.0

This commit is contained in:
Neo committed 2025-12-19 05:51:58 -08:00
1 parent 1a0c7fd3c2
commit f79dcf067a
3791 files changed
+248032 -76372

No files matched your search

+292 -165
View File
@@ -12,7 +12,7 @@
namespace IPS\Api;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
@@ -120,158 +120,168 @@ class _OAuthClient extends \IPS\Node\Model
$form->addTab('oauth_basic_settings');
$form->addHeader('oauth_basic_settings');
$form->add( new \IPS\Helpers\Form\Translatable( 'oauth_client_name', NULL, TRUE, array( 'app' => 'core', 'key' => ( $this->client_id ? "core_oauth_client_{$this->client_id}" : NULL ) ) ) );
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_client_type', $type, TRUE, array(
'options' => array(
'invision' => 'client_type_invision',
'wordpress' => 'client_type_wordpress',
'confidential' => 'client_type_confidential',
'public' => 'client_type_public',
),
'toggles' => array(
'invision' => array( 'oauth_grant_types_invision', 'oauth_invision_endpoint' ),
'wordpress' => array( 'oauth_wordpress_endpoint' ),
'confidential' => array( 'oauth_grant_types_confidential', 'oauth_redirect_uris', 'oauth_choose_scopes', 'oauth_header_oauth_access_tokens', 'oauth_access_token_length', 'oauth_tab_oauth_scopes' ),
'public' => array( 'oauth_grant_types_public', 'oauth_redirect_uris', 'oauth_choose_scopes', 'oauth_header_oauth_access_tokens', 'oauth_access_token_length', 'oauth_tab_oauth_scopes' ),
)
) ) );
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_invision_grant_type', $this->client_id ? $this->grant_types : 'authorization_code', NULL, array(
'options' => array(
'authorization_code' => 'invision_grant_type_server_authorization_code',
'password' => 'invision_grant_type_server_password',
),
), NULL, NULL, NULL, 'oauth_grant_types_invision' ) );
$confidentialGrant = new \IPS\Helpers\Form\CheckboxSet( 'oauth_grant_types_confidential', $this->client_id ? explode( ',', $this->grant_types ) : array( 'authorization_code' ), NULL, array(
'options' => array(
'authorization_code' => 'grant_type_authorization_code',
'implicit' => 'grant_type_implicit',
'password' => 'grant_type_password',
'client_credentials' => 'grant_type_client_credentials'
),
'toggles' => array(
'authorization_code' => array( 'oauth_use_refresh_tokens' )
)
), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type === 'confidential' ) {
throw new \DomainException('form_required');
}
}, NULL, NULL, 'oauth_grant_types_confidential' );
$confidentialGrant->label = \IPS\Member::loggedIn()->language()->addToStack('oauth_grant_types');
$form->add( $confidentialGrant );
$publicGrant = new \IPS\Helpers\Form\CheckboxSet( 'oauth_grant_types_public', $this->client_id ? explode( ',', $this->grant_types ) : array( 'implicit' ), NULL, array(
'options' => array(
'authorization_code' => 'grant_type_authorization_code',
'implicit' => 'grant_type_implicit',
'password' => 'grant_type_password',
),
'toggles' => array(
'authorization_code' => array( 'oauth_use_refresh_tokens' )
)
), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type === 'public' ) {
throw new \DomainException('form_required');
}
}, NULL, NULL, 'oauth_grant_types_public' );
$publicGrant->label = \IPS\Member::loggedIn()->language()->addToStack('oauth_grant_types');
$form->add( $publicGrant );
$redirectUris = json_decode( $this->redirect_uris, TRUE );
$form->add( new \IPS\Helpers\Form\Url( 'oauth_invision_endpoint', isset( $redirectUris[0] ) ? preg_replace( '#/oauth/callback/$#i', '/', $redirectUris[0] ) : NULL, NULL, array( 'placeholder' => 'https://othercommunity.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type == 'invision' ) {
throw new \DomainException('form_required');
}
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
throw new \DomainException('oauth_redirect_uris_no_fragment');
}
if ( $val and rtrim( (string) $val, '/' ) === rtrim( \IPS\Settings::i()->base_url, '/' ) ) {
throw new \DomainException('oauth_invision_endpoint_internal');
}
}, NULL, NULL, 'oauth_invision_endpoint' ) );
$form->add( new \IPS\Helpers\Form\Url( 'oauth_wordpress_endpoint', isset( $redirectUris[0] ) ? preg_replace( '#/oauthcallback/$#i', '', $redirectUris[0] ) : NULL, NULL, array( 'placeholder' => 'https://wordpress.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type == 'wordpress' ) {
throw new \DomainException('form_required');
}
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
throw new \DomainException('oauth_redirect_uris_no_fragment');
}
}, NULL, NULL, 'oauth_wordpress_endpoint' ) );
$form->add( new \IPS\Helpers\Form\Stack( 'oauth_redirect_uris', $redirectUris, NULL, array( 'stackFieldType' => 'Url', 'placeholder' => 'https://www.example.com/redirect_uri', 'allowedProtocols' => NULL ), function( $val ) {
if ( !in_array( \IPS\Request::i()->oauth_client_type, array('invision', 'wordpress') ) ) {
$chosenGrantTypes = \IPS\Request::i()->oauth_client_type === 'public' ? \IPS\Request::i()->oauth_grant_types_public : \IPS\Request::i()->oauth_grant_types_confidential;
if ( !$val and ( isset( $chosenGrantTypes['authorization_code'] ) or isset( $chosenGrantTypes['implicit'] ) ) ) {
if ( $type !== 'mobile' )
{
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_client_type', $type, TRUE, array(
'options' => array(
'invision' => 'client_type_invision',
'wordpress' => 'client_type_wordpress',
'confidential' => 'client_type_confidential',
'public' => 'client_type_public',
),
'toggles' => array(
'invision' => array( 'oauth_grant_types_invision', 'oauth_invision_endpoint' ),
'wordpress' => array( 'oauth_wordpress_endpoint' ),
'confidential' => array( 'oauth_grant_types_confidential', 'oauth_redirect_uris', 'oauth_choose_scopes', 'oauth_header_oauth_access_tokens', 'oauth_access_token_length', 'oauth_tab_oauth_scopes' ),
'public' => array( 'oauth_grant_types_public', 'oauth_redirect_uris', 'oauth_choose_scopes', 'oauth_header_oauth_access_tokens', 'oauth_access_token_length', 'oauth_tab_oauth_scopes' ),
)
) ) );
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_invision_grant_type', $this->client_id ? $this->grant_types : 'authorization_code', NULL, array(
'options' => array(
'authorization_code' => 'invision_grant_type_server_authorization_code',
'password' => 'invision_grant_type_server_password',
),
), NULL, NULL, NULL, 'oauth_grant_types_invision' ) );
$confidentialGrant = new \IPS\Helpers\Form\CheckboxSet( 'oauth_grant_types_confidential', $this->client_id ? explode( ',', $this->grant_types ) : array( 'authorization_code' ), NULL, array(
'options' => array(
'authorization_code' => 'grant_type_authorization_code',
'implicit' => 'grant_type_implicit',
'password' => 'grant_type_password',
'client_credentials' => 'grant_type_client_credentials'
),
'toggles' => array(
'authorization_code' => array( 'oauth_pkce', 'oauth_use_refresh_tokens' )
)
), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type === 'confidential' ) {
throw new \DomainException('form_required');
}
}, NULL, NULL, 'oauth_grant_types_confidential' );
$confidentialGrant->label = \IPS\Member::loggedIn()->language()->addToStack('oauth_grant_types');
$form->add( $confidentialGrant );
$publicGrant = new \IPS\Helpers\Form\CheckboxSet( 'oauth_grant_types_public', $this->client_id ? explode( ',', $this->grant_types ) : array( 'implicit' ), NULL, array(
'options' => array(
'authorization_code' => 'grant_type_authorization_code',
'implicit' => 'grant_type_implicit',
'password' => 'grant_type_password',
),
'toggles' => array(
'authorization_code' => array( 'oauth_pkce', 'oauth_use_refresh_tokens' )
)
), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type === 'public' ) {
throw new \DomainException('form_required');
}
}, NULL, NULL, 'oauth_grant_types_public' );
$publicGrant->label = \IPS\Member::loggedIn()->language()->addToStack('oauth_grant_types');
$form->add( $publicGrant );
$redirectUris = json_decode( $this->redirect_uris, TRUE );
$form->add( new \IPS\Helpers\Form\Url( 'oauth_invision_endpoint', isset( $redirectUris[0] ) ? preg_replace( '#/oauth/callback/$#i', '/', $redirectUris[0] ) : NULL, NULL, array( 'placeholder' => 'https://othercommunity.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type == 'invision' ) {
throw new \DomainException('form_required');
}
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
throw new \DomainException('oauth_redirect_uris_no_fragment');
}
}
}, NULL, NULL, 'oauth_redirect_uris' ) );
if ( $val and rtrim( (string) $val, '/' ) === rtrim( \IPS\Settings::i()->base_url, '/' ) ) {
throw new \DomainException('oauth_invision_endpoint_internal');
}
}, NULL, NULL, 'oauth_invision_endpoint' ) );
$form->add( new \IPS\Helpers\Form\Url( 'oauth_wordpress_endpoint', isset( $redirectUris[0] ) ? $redirectUris[0] : NULL, NULL, array( 'placeholder' => 'https://wordpress.example.com/', 'allowedProtocols' => NULL ), function( $val ) {
if ( !$val and \IPS\Request::i()->oauth_client_type == 'wordpress' ) {
throw new \DomainException('form_required');
}
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
throw new \DomainException('oauth_redirect_uris_no_fragment');
}
}, NULL, NULL, 'oauth_wordpress_endpoint' ) );
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_pkce', $this->pkce ?: 'none', FALSE, array( 'options' => array( 'S256' => 'oauth_pkce_256', 'plain' => 'oauth_pkce_plain', 'none' => 'oauth_pkce_none' ) ), NULL, NULL, NULL, 'oauth_pkce' ) );
$form->add( new \IPS\Helpers\Form\Stack( 'oauth_redirect_uris', $redirectUris, NULL, array( 'stackFieldType' => 'Url', 'placeholder' => 'https://www.example.com/redirect_uri', 'allowedProtocols' => NULL ), function( $val ) {
if ( !\in_array( \IPS\Request::i()->oauth_client_type, array('invision', 'wordpress') ) ) {
$chosenGrantTypes = \IPS\Request::i()->oauth_client_type === 'public' ? \IPS\Request::i()->oauth_grant_types_public : \IPS\Request::i()->oauth_grant_types_confidential;
if ( !$val and ( isset( $chosenGrantTypes['authorization_code'] ) or isset( $chosenGrantTypes['implicit'] ) ) ) {
throw new \DomainException('form_required');
}
if ( $val and $val instanceof \IPS\Http\Url and $val->data[ \IPS\Http\Url::COMPONENT_FRAGMENT ] ) {
throw new \DomainException('oauth_redirect_uris_no_fragment');
}
}
}, NULL, NULL, 'oauth_redirect_uris' ) );
}
$form->addHeader('oauth_authorization_screen');
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_prompt', $this->prompt, FALSE, array( 'options' => array( 'automatic' => 'oauth_prompt_automatic', 'reauthorize' => 'oauth_prompt_reauthorize', 'login' => 'oauth_prompt_login' ) ) ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_choose_scopes', $this->choose_scopes, FALSE, array(), NULL, NULL, NULL, 'oauth_choose_scopes' ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_ucp', $this->ucp, FALSE ) );
$form->addHeader('oauth_access_tokens');
$form->add( new \IPS\Helpers\Form\Number( 'oauth_access_token_length', $this->access_token_length, NULL, array( 'unlimited' => 0, 'unlimitedLang' => 'never' ), NULL, NULL, \IPS\Member::loggedIn()->language()->addToStack('hours'), 'oauth_access_token_length' ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_use_refresh_tokens', $this->use_refresh_tokens, NULL, array( 'togglesOn' => array( 'oauth_refresh_token_length' ) ), NULL, NULL, NULL, 'oauth_use_refresh_tokens' ) );
$form->add( new \IPS\Helpers\Form\Number( 'oauth_refresh_token_length', $this->refresh_token_length, NULL, array( 'unlimited' => 0, 'unlimitedLang' => 'never' ), NULL, NULL, \IPS\Member::loggedIn()->language()->addToStack('days'), 'oauth_refresh_token_length' ) );
$form->addTab('oauth_scopes');
$form->addMessage('oauth_scopes_blurb');
$matrix = new \IPS\Helpers\Form\Matrix;
$matrix->classes[] = 'cApiPermissionsMatrix';
$matrix->langPrefix = 'oauth_scope_';
$matrix->columns = array(
'name' => function( $key, $value, $data )
{
return new \IPS\Helpers\Form\Custom( $key, $value, FALSE, array(
'getHtml' => function( $field )
{
return \IPS\Theme::i()->getTemplate( 'api' )->oauthScopeField( $field->name, $field->value );
}
) );
},
'endpoints' => function( $key, $value, $data )
{
return new \IPS\Helpers\Form\Custom( $key, $value ?: array(), FALSE, array(
'getHtml' => function( $field )
{
$endpoints = \IPS\Api\Controller::getAllEndpoints('member');
foreach ( $endpoints as $key => $endpoint )
{
$pieces = explode('/', $key);
$endpointTree[ $pieces[0] ][ $pieces[1] ][ $key ] = $endpoint;
}
return \IPS\Theme::i()->getTemplate( 'api' )->permissionsFieldHtml( $endpointTree, $field->name, $field->value );
}
) );
}
);
if ( !$this->client_id )
$form->add( new \IPS\Helpers\Form\Radio( 'oauth_prompt', $this->prompt, FALSE, array( 'options' => array( 'none' => 'oauth_prompt_none', 'automatic' => 'oauth_prompt_automatic', 'reauthorize' => 'oauth_prompt_reauthorize', 'login' => 'oauth_prompt_login' ) ) ) );
if ( $type !== 'mobile' )
{
$matrix->rows[] = array(
'name' => array( 'key' => 'profile', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_profile') ),
'endpoints' => array(
'core/me/GETindex' => array( 'access' => TRUE, 'log' => FALSE ),
)
);
$matrix->rows[] = array(
'name' => array( 'key' => 'email', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_email') ),
'endpoints' => array(
'core/me/GETitem' => array( 'access' => TRUE, 'log' => FALSE ),
)
);
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_choose_scopes', $this->choose_scopes, FALSE, array(), NULL, NULL, NULL, 'oauth_choose_scopes' ) );
}
elseif ( $this->scopes and $scopes = json_decode( $this->scopes, TRUE ) )
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_ucp', $this->ucp, FALSE ) );
if ( $type !== 'mobile' )
{
foreach ( $scopes as $key => $data )
$form->addHeader('oauth_access_tokens');
$form->add( new \IPS\Helpers\Form\Interval( 'oauth_access_token_length', $this->access_token_length, NULL, array( 'valueAs' => \IPS\Helpers\Form\Interval::HOURS, 'unlimited' => 0, 'unlimitedLang' => 'forever' ), NULL, NULL, NULL, 'oauth_access_token_length' ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'oauth_use_refresh_tokens', $this->use_refresh_tokens, NULL, array( 'togglesOn' => array( 'oauth_refresh_token_length' ) ), NULL, NULL, NULL, 'oauth_use_refresh_tokens' ) );
$form->add( new \IPS\Helpers\Form\Interval( 'oauth_refresh_token_length', $this->refresh_token_length, NULL, array( 'valueAs' => \IPS\Helpers\Form\Interval::DAYS, 'unlimited' => 0, 'unlimitedLang' => 'forever' ), NULL, NULL, NULL, 'oauth_refresh_token_length' ) );
$form->addTab('oauth_scopes');
$form->addMessage('oauth_scopes_blurb');
$matrix = new \IPS\Helpers\Form\Matrix;
$matrix->classes[] = 'cApiPermissionsMatrix';
$matrix->langPrefix = 'oauth_scope_';
$matrix->columns = array(
'name' => function( $key, $value, $data )
{
return new \IPS\Helpers\Form\Custom( $key, $value, FALSE, array(
'getHtml' => function( $field )
{
return \IPS\Theme::i()->getTemplate( 'api' )->oauthScopeField( $field->name, $field->value );
}
) );
},
'endpoints' => function( $key, $value, $data )
{
return new \IPS\Helpers\Form\Custom( $key, $value ?: array(), FALSE, array(
'getHtml' => function( $field )
{
$endpoints = \IPS\Api\Controller::getAllEndpoints();
foreach ( $endpoints as $key => $endpoint )
{
$pieces = explode('/', $key);
$endpointTree[ $pieces[0] ][ $pieces[1] ][ $key ] = $endpoint;
}
return \IPS\Theme::i()->getTemplate( 'api' )->permissionsFieldHtml( $endpointTree, $field->name, $field->value );
}
) );
}
);
if ( !$this->client_id )
{
$matrix->rows[] = array(
'name' => array( 'key' => $key, 'desc' => $data['description'] ),
'endpoints' => $data['endpoints']
'name' => array( 'key' => 'profile', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_profile') ),
'endpoints' => array(
'core/me/GETindex' => array( 'access' => TRUE, 'log' => FALSE ),
)
);
$matrix->rows[] = array(
'name' => array( 'key' => 'email', 'desc' => \IPS\Member::loggedIn()->language()->get('oauth_default_scope_email') ),
'endpoints' => array(
'core/me/GETitem' => array( 'access' => TRUE, 'log' => FALSE ),
)
);
}
elseif ( $this->scopes and $scopes = json_decode( $this->scopes, TRUE ) )
{
foreach ( $scopes as $key => $data )
{
$matrix->rows[] = array(
'name' => array( 'key' => $key, 'desc' => $data['description'] ),
'endpoints' => $data['endpoints']
);
}
}
$form->addMatrix( 'scopes', $matrix );
}
$form->addMatrix( 'scopes', $matrix );
}
/**
@@ -288,8 +298,21 @@ class _OAuthClient extends \IPS\Node\Model
public function formatFormValues( $values )
{
/* Normalise the settings */
$originalClientType = $values['oauth_client_type'];
if ( $values['oauth_client_type'] === 'invision' )
$originalClientType = isset( $values['oauth_client_type'] ) ? $values['oauth_client_type'] : $this->type;
if ( $this->type === 'mobile' )
{
$values['oauth_client_type'] = 'mobile';
foreach ( static::mobileAppValues() as $k => $v )
{
$values["oauth_{$k}"] = $v;
}
$values['oauth_grant_types_public'] = $values['oauth_grant_types'];
$values['scopes'] = $values['oauth_scopes'];
$values['oauth_pkce'] = 'S256';
}
elseif ( $values['oauth_client_type'] === 'invision' )
{
$values['oauth_client_type'] = 'confidential';
$values['oauth_grant_types_confidential'] = array( $values['oauth_invision_grant_type'] );
@@ -313,12 +336,13 @@ class _OAuthClient extends \IPS\Node\Model
)
);
$values['oauth_type'] = 'invision';
$values['oauth_pkce'] = 'none';
}
elseif ( $values['oauth_client_type'] === 'wordpress' )
{
$values['oauth_client_type'] = 'confidential';
$values['oauth_grant_types_confidential'] = array( 'authorization_code' );
$values['oauth_redirect_uris'] = array( rtrim( $values['oauth_wordpress_endpoint'], '/' ) . '/oauthcallback' );
$values['oauth_redirect_uris'] = array( rtrim( $values['oauth_wordpress_endpoint'], '/' ) );
$values['oauth_choose_scopes'] = FALSE;
$values['oauth_access_token_length'] = 168;
$values['oauth_use_refresh_tokens'] = TRUE;
@@ -333,6 +357,7 @@ class _OAuthClient extends \IPS\Node\Model
)
);
$values['oauth_type'] = 'wordpress';
$values['oauth_pkce'] = 'none';
}
else
{
@@ -341,7 +366,7 @@ class _OAuthClient extends \IPS\Node\Model
unset( $values['oauth_invision_grant_type'] );
unset( $values['oauth_invision_endpoint'] );
unset( $values['oauth_wordpress_endpoint'] );
/* Generate Client ID */
if ( !$this->client_id )
{
@@ -425,6 +450,27 @@ class _OAuthClient extends \IPS\Node\Model
return FALSE;
}
/**
* [Node] Does the currently logged in user have permission to delete this node?
*
* @return bool
*/
public function canDelete()
{
return $this->type !== 'mobile'; // Admin can deregister community which will in turn delete the client
}
/**
* [Node] Get whether or not this node is locked to current enabled/disabled status
*
* @note Return value NULL indicates the node cannot be enabled/disabled
* @return bool|null
*/
protected function get__locked()
{
return $this->type === 'mobile';
}
/**
* [Node] Get buttons to display in tree
* Example code explains return value
@@ -475,13 +521,18 @@ class _OAuthClient extends \IPS\Node\Model
/**
* Generate or renew an access token
*
* @param \IPS\Member|NULL $member The member or NULL for client_credentials
* @param array|null $scopes Array of scopes or NULL if none were requested
* @param bool $skipRefreshToken If TRUE, will not generater a refresh token (for example, when using implicit grant type)
* @param string $authorizationCode The authorization code which generated the token, if applicable
* @param \IPS\Member|NULL $member The member or NULL for client_credentials
* @param array|null $scopes Array of scopes or NULL if none were requested
* @param string $grantType Type of grant
* @param bool $skipRefreshToken If TRUE, will not generate a refresh token (for example, when using implicit grant type)
* @param string|NULL $authorizationCode The authorization code which generated the token, if applicable
* @param string|NULL $userAgent The user agent that the user performed authentication on, if known
* @param string|NULL $issueUserAgent The user agent that the access token was issued to, if known
* @param \IPS\Member\Device|NULL $device The device used to obtain this access token, if known
* @param array $tokenToRefresh If we are refreshing, the existing access token to refresh
* @return array
*/
public function generateAccessToken( \IPS\Member $member = NULL, $scopes, $grantType, $skipRefreshToken = FALSE, $authorizationCode = NULL )
public function generateAccessToken( \IPS\Member $member = NULL, $scopes, $grantType, $skipRefreshToken = FALSE, $authorizationCode = NULL, $authUserAgent = NULL, $grantUserAgent = NULL, \IPS\Member\Device $device = NULL, $tokenToRefresh = NULL )
{
do
{
@@ -497,33 +548,57 @@ class _OAuthClient extends \IPS\Node\Model
'refresh_token' => NULL,
'refresh_token_expires' => $this->refresh_token_length ? ( time() + ( $this->refresh_token_length * 86400 ) ) : NULL,
'scope' => $scopes ? json_encode( $scopes ) : NULL,
'authorization_code' => $authorizationCode,
'issued' => time()
'authorization_code' => $authorizationCode,
'issued' => time(),
'auth_user_agent' => $authUserAgent,
'issue_user_agent' => $grantUserAgent,
'device_key' => $device ? $device->device_key : NULL
);
if ( $this->use_refresh_tokens and !$skipRefreshToken )
if ( $this->use_refresh_tokens )
{
do
if ( !$skipRefreshToken )
{
$data['refresh_token'] = \IPS\Login::generateRandomString( 64 );
do
{
$data['refresh_token'] = \IPS\Login::generateRandomString( 64 );
}
while ( $this->validateRefreshToken( $data['refresh_token'] ) );
if ( $this->refresh_token_length )
{
$data['refresh_token_expires'] = time() + ( $this->refresh_token_length * 86400 );
}
else
{
$data['refresh_token_expires'] = NULL;
}
}
while ( $this->validateRefreshToken( $data['refresh_token'] ) );
if ( $this->refresh_token_length )
elseif ( $tokenToRefresh )
{
$data['refresh_token_expires'] = time() + ( $this->refresh_token_length * 86400 );
}
else
{
$data['refresh_token_expires'] = NULL;
$data['refresh_token'] = $tokenToRefresh['refresh_token'];
$data['refresh_token_expires'] = $tokenToRefresh['refresh_token_expires'];
}
}
\IPS\Db::i()->insert( 'core_oauth_server_access_tokens', $data );
if ( $member )
if ( $grantType === 'refresh_token' and $tokenToRefresh )
{
$member->logHistory( 'core', 'oauth', array( 'type' => 'issued_access_token', 'client' => $this->client_id, 'grant' => $grantType, 'scopes' => $scopes ), FALSE );
\IPS\Db::i()->update( 'core_oauth_server_access_tokens', $data, array( 'client_id=? AND access_token=?', $tokenToRefresh['client_id'], $tokenToRefresh['access_token'] ) );
}
else
{
\IPS\Db::i()->insert( 'core_oauth_server_access_tokens', $data );
if ( $member )
{
$member->logHistory( 'core', 'oauth', array( 'type' => 'issued_access_token', 'client' => $this->client_id, 'grant' => $grantType, 'scopes' => $scopes ), FALSE );
}
}
if ( $device )
{
$device->last_seen = time();
$device->save();
$device->logIpAddress( \IPS\Request::i()->ipAddress() );
}
$data['access_token'] = $this->client_id . '_' . $data['access_token'];
@@ -531,6 +606,32 @@ class _OAuthClient extends \IPS\Node\Model
return $data;
}
/**
* Get access token details, checking it isn't expired
*
* @param string $accessToken The access token
* @return \IPS\Member|NULL
* @throws \UnderflowException
* @throws \IPS\Api\Exception
*/
public static function accessTokenDetails( $accessToken )
{
$exploded = explode( '_', $accessToken );
if ( !isset( $exploded[0] ) or !isset( $exploded[1] ) )
{
throw new \UnderflowException;
}
$return = \IPS\Db::i()->select( '*', 'core_oauth_server_access_tokens', array( 'client_id=? AND access_token=?', $exploded[0], $exploded[1] ) )->first();
if ( $return['access_token_expires'] and $return['access_token_expires'] < time() )
{
throw new \IPS\Api\Exception( 'EXPIRED_ACCESS_TOKEN', '1S290/E', 401, 'invalid_token' );
}
return $return;
}
/**
* Validate an access token
*
@@ -582,7 +683,7 @@ class _OAuthClient extends \IPS\Node\Model
}
}
if ( count( array_diff( $scopes, $row['scope'] ? json_decode( $row['scope'] ) : array() ) ) )
if ( \count( array_diff( $scopes, $row['scope'] ? json_decode( $row['scope'] ) : array() ) ) )
{
continue;
}
@@ -666,5 +767,31 @@ class _OAuthClient extends \IPS\Node\Model
return parent::delete();
}
/**
* Get special values for mobile app
*
* @return void
*/
final public static function mobileAppValues()
{
$redirect_uris = [ \IPS\APP_MULTICOMMUNITY_SCHEMA . ':///auth' ];
if ( \IPS\Settings::i()->mobile_app_redirect_scheme )
{
$redirect_uris[] = \IPS\Settings::i()->mobile_app_redirect_scheme . ':///auth';
}
return array(
'grant_types' => array('authorization_code'),
'redirect_uris' => $redirect_uris,
'access_token_length' => 168,
'use_refresh_tokens' => TRUE,
'refresh_token_length' => NULL,
'scopes' => array(),
'choose_scopes' => FALSE,
'type' => 'mobile',
'graphql' => TRUE
);
}
}