2012-08-03 15:47:05 +04:00
|
|
|
<?php
|
|
|
|
/**
|
|
|
|
* ownCloud
|
|
|
|
*
|
|
|
|
* @author Michael Gapczynski
|
2012-08-30 18:02:31 +04:00
|
|
|
* @author Tom Needham
|
2012-08-03 15:47:05 +04:00
|
|
|
* @copyright 2012 Michael Gapczynski mtgap@owncloud.com
|
2012-08-30 18:02:31 +04:00
|
|
|
* @copyright 2012 Tom Needham tom@owncloud.com
|
2012-08-03 15:47:05 +04:00
|
|
|
*
|
|
|
|
* This library is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU AFFERO GENERAL PUBLIC LICENSE
|
|
|
|
* License as published by the Free Software Foundation; either
|
|
|
|
* version 3 of the License, or any later version.
|
|
|
|
*
|
|
|
|
* This library is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU AFFERO GENERAL PUBLIC LICENSE for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public
|
|
|
|
* License along with this library. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
2012-09-04 15:10:42 +04:00
|
|
|
class OC_OAuth_Store extends OAuthDataStore {
|
|
|
|
|
|
|
|
static private $MAX_TIMESTAMP_DIFFERENCE = 300;
|
2012-08-30 18:02:31 +04:00
|
|
|
|
|
|
|
function lookup_consumer($consumer_key) {
|
2012-09-04 15:10:42 +04:00
|
|
|
$query = OC_DB::prepare("SELECT `key`, `secret`, `callback_success` FROM `*PREFIX*oauth_consumers` WHERE `key` = ?");
|
2012-08-30 18:02:31 +04:00
|
|
|
$results = $query->execute(array($consumer_key));
|
|
|
|
if($results->numRows()==0){
|
|
|
|
return NULL;
|
|
|
|
} else {
|
|
|
|
$details = $results->fetchRow();
|
2012-09-04 15:10:42 +04:00
|
|
|
$callback = !empty($details['callback_success']) ? $details['callback_success'] : NULL;
|
2012-08-30 18:02:31 +04:00
|
|
|
return new OAuthConsumer($details['key'], $details['secret'], $callback);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
function lookup_token($consumer, $token_type, $token) {
|
|
|
|
$query = OC_DB::prepare("SELECT `key`, `secret`, `type` FROM `*PREFIX*oauth_tokens` WHERE `consumer_key` = ? AND `key` = ? AND `type` = ?");
|
|
|
|
$results = $query->execute(array($consumer->key, $token->key, $token_type));
|
|
|
|
if($results->numRows()==0){
|
|
|
|
return NULL;
|
|
|
|
} else {
|
|
|
|
$token = $results->fetchRow();
|
|
|
|
return new OAuthToken($token['key'], $token['secret']);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
function lookup_nonce($consumer, $token, $nonce, $timestamp) {
|
|
|
|
$query = OC_DB::prepare("INSERT INTO `*PREFIX*oauth_nonce` (`consumer_key`, `token`, `timestamp`, `nonce`) VALUES (?, ?, ?, ?)");
|
2012-09-04 15:10:42 +04:00
|
|
|
$affectedrows = $query->execute(array($consumer->key, $token, $timestamp, $nonce));
|
2012-08-30 18:02:31 +04:00
|
|
|
// Delete all timestamps older than the one passed
|
|
|
|
$query = OC_DB::prepare("DELETE FROM `*PREFIX*oauth_nonce` WHERE `consumer_key` = ? AND `token` = ? AND `timestamp` < ?");
|
2012-09-04 15:10:42 +04:00
|
|
|
$result = $query->exec(array($consumer->key, $token, $timestamp - self::$MAX_TIMESTAMP_DIFFERENCE));
|
2012-08-30 18:02:31 +04:00
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
|
2012-09-04 15:10:42 +04:00
|
|
|
function new_token($consumer, $token_type) {
|
2012-08-30 18:02:31 +04:00
|
|
|
$key = md5(time());
|
|
|
|
$secret = time() + time();
|
|
|
|
$token = new OAuthToken($key, md5(md5($secret)));
|
2012-09-04 15:10:42 +04:00
|
|
|
$query = OC_DB::prepare("INSERT INTO `*PREFIX*oauth_tokens` (`consumer_key`, `key`, `secret`, `type`, `timestamp`) VALUES (?, ?, ?, ?, ?, ?)");
|
|
|
|
$result = $query->execute(array($consumer->key, $key, $secret, $token_type, time()));
|
2012-08-30 18:02:31 +04:00
|
|
|
return $token;
|
|
|
|
}
|
|
|
|
|
2012-09-04 15:10:42 +04:00
|
|
|
function new_request_token($consumer, $callback = null) {
|
|
|
|
return $this->new_token($consumer, 'request');
|
2012-08-30 18:02:31 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
function authorise_request_token($token, $consumer, $uid) {
|
|
|
|
$query = OC_DB::prepare("UPDATE `*PREFIX*oauth_tokens` SET uid = ? WHERE `consumer_key` = ? AND `key` = ? AND `type` = ?");
|
|
|
|
$query->execute(array($uid, $consumer->key, $token->key, 'request'));
|
|
|
|
// TODO Return oauth_verifier
|
|
|
|
}
|
|
|
|
|
|
|
|
function new_access_token($token, $consumer, $verifier = null) {
|
|
|
|
$query = OC_DB::prepare("SELECT `timestamp`, `scope` FROM `*PREFIX*oauth_tokens` WHERE `consumer_key` = ? AND `key` = ? AND `type` = ?");
|
|
|
|
$result = $query->execute(array($consumer->key, $token->key, 'request'))->fetchRow();
|
|
|
|
if (isset($result['timestamp'])) {
|
|
|
|
if ($timestamp + self::MAX_REQUEST_TOKEN_TTL < time()) {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
$accessToken = $this->new_token($consumer, 'access', $result['scope']);
|
|
|
|
}
|
|
|
|
// Delete request token
|
|
|
|
$query = OC_DB::prepare("DELETE FROM `*PREFIX*oauth_tokens` WHERE `key` = ? AND `type` = ?");
|
|
|
|
$query->execute(array($token->key, 'request'));
|
|
|
|
return $accessToken;
|
|
|
|
}
|
2012-08-03 15:47:05 +04:00
|
|
|
|
|
|
|
}
|