2017-05-05 00:46:59 +03:00
|
|
|
<?php
|
|
|
|
/**
|
|
|
|
* @copyright Copyright (c) 2017 Lukas Reschke <lukas@statuscode.ch>
|
|
|
|
*
|
|
|
|
* @license GNU AGPL version 3 or any later version
|
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License as
|
|
|
|
* published by the Free Software Foundation, either version 3 of the
|
|
|
|
* License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU Affero General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public License
|
|
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
namespace OCA\OAuth2\Controller;
|
|
|
|
|
|
|
|
use OC\Authentication\Token\DefaultTokenMapper;
|
|
|
|
use OCA\OAuth2\Db\AccessTokenMapper;
|
2018-05-16 12:50:37 +03:00
|
|
|
use OCA\OAuth2\Db\ClientMapper;
|
|
|
|
use OCA\OAuth2\Exceptions\AccessTokenNotFoundException;
|
2017-05-05 00:46:59 +03:00
|
|
|
use OCP\AppFramework\Controller;
|
2018-05-16 12:50:37 +03:00
|
|
|
use OCP\AppFramework\Http;
|
2017-05-05 00:46:59 +03:00
|
|
|
use OCP\AppFramework\Http\JSONResponse;
|
|
|
|
use OCP\IRequest;
|
|
|
|
use OCP\Security\ICrypto;
|
|
|
|
use OCP\Security\ISecureRandom;
|
|
|
|
|
|
|
|
class OauthApiController extends Controller {
|
|
|
|
/** @var AccessTokenMapper */
|
|
|
|
private $accessTokenMapper;
|
2018-05-16 12:50:37 +03:00
|
|
|
/** @var ClientMapper */
|
|
|
|
private $clientMapper;
|
2017-05-05 00:46:59 +03:00
|
|
|
/** @var ICrypto */
|
|
|
|
private $crypto;
|
|
|
|
/** @var DefaultTokenMapper */
|
|
|
|
private $defaultTokenMapper;
|
|
|
|
/** @var ISecureRandom */
|
|
|
|
private $secureRandom;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param string $appName
|
|
|
|
* @param IRequest $request
|
|
|
|
* @param ICrypto $crypto
|
|
|
|
* @param AccessTokenMapper $accessTokenMapper
|
2018-05-16 12:50:37 +03:00
|
|
|
* @param ClientMapper $clientMapper
|
2017-05-05 00:46:59 +03:00
|
|
|
* @param DefaultTokenMapper $defaultTokenMapper
|
|
|
|
* @param ISecureRandom $secureRandom
|
|
|
|
*/
|
|
|
|
public function __construct($appName,
|
|
|
|
IRequest $request,
|
|
|
|
ICrypto $crypto,
|
|
|
|
AccessTokenMapper $accessTokenMapper,
|
2018-05-16 12:50:37 +03:00
|
|
|
ClientMapper $clientMapper,
|
2017-05-05 00:46:59 +03:00
|
|
|
DefaultTokenMapper $defaultTokenMapper,
|
|
|
|
ISecureRandom $secureRandom) {
|
|
|
|
parent::__construct($appName, $request);
|
|
|
|
$this->crypto = $crypto;
|
|
|
|
$this->accessTokenMapper = $accessTokenMapper;
|
2018-05-16 12:50:37 +03:00
|
|
|
$this->clientMapper = $clientMapper;
|
2017-05-05 00:46:59 +03:00
|
|
|
$this->defaultTokenMapper = $defaultTokenMapper;
|
|
|
|
$this->secureRandom = $secureRandom;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @PublicPage
|
|
|
|
* @NoCSRFRequired
|
|
|
|
*
|
2018-05-16 12:50:37 +03:00
|
|
|
* @param string $grant_type
|
2017-05-05 00:46:59 +03:00
|
|
|
* @param string $code
|
2018-05-16 12:50:37 +03:00
|
|
|
* @param string $refresh_token
|
2018-05-16 11:35:18 +03:00
|
|
|
* @param string $client_id
|
|
|
|
* @param string $client_secret
|
2017-05-05 00:46:59 +03:00
|
|
|
* @return JSONResponse
|
|
|
|
*/
|
2018-05-16 12:50:37 +03:00
|
|
|
public function getToken($grant_type, $code, $refresh_token, $client_id, $client_secret) {
|
|
|
|
|
|
|
|
if ($grant_type !== 'authorization_code' && $grant_type !== 'refresh_token') {
|
|
|
|
return new JSONResponse([
|
|
|
|
'error' => 'invalid_grant',
|
|
|
|
], Http::STATUS_BAD_REQUEST);
|
|
|
|
}
|
|
|
|
|
|
|
|
// We handle the initial and refresh tokens the same way
|
|
|
|
if ($grant_type === 'refresh_token' ) {
|
|
|
|
$code = $refresh_token;
|
|
|
|
}
|
|
|
|
|
|
|
|
try {
|
|
|
|
$accessToken = $this->accessTokenMapper->getByCode($code);
|
|
|
|
} catch (AccessTokenNotFoundException $e) {
|
|
|
|
return new JSONResponse([
|
|
|
|
'error' => 'invalid_request',
|
|
|
|
], Http::STATUS_BAD_REQUEST);
|
|
|
|
}
|
|
|
|
|
|
|
|
try {
|
|
|
|
$client = $this->clientMapper->getByUid($accessToken->getClientId());
|
|
|
|
} catch (ClientNotFoundException $e) {
|
|
|
|
return new JSONResponse([
|
|
|
|
'error' => 'invalid_request',
|
|
|
|
], Http::STATUS_BAD_REQUEST);
|
|
|
|
}
|
|
|
|
|
|
|
|
if ($client->getClientIdentifier() !== $client_id || $client->getSecret() !== $client_secret) {
|
|
|
|
return new JSONResponse([
|
|
|
|
'error' => 'invalid_client',
|
|
|
|
], Http::STATUS_BAD_REQUEST);
|
|
|
|
}
|
|
|
|
|
2017-05-05 00:46:59 +03:00
|
|
|
$decryptedToken = $this->crypto->decrypt($accessToken->getEncryptedToken(), $code);
|
|
|
|
$newCode = $this->secureRandom->generate(128);
|
|
|
|
$accessToken->setHashedCode(hash('sha512', $newCode));
|
|
|
|
$accessToken->setEncryptedToken($this->crypto->encrypt($decryptedToken, $newCode));
|
|
|
|
$this->accessTokenMapper->update($accessToken);
|
|
|
|
|
|
|
|
return new JSONResponse(
|
|
|
|
[
|
|
|
|
'access_token' => $decryptedToken,
|
2017-05-05 01:19:28 +03:00
|
|
|
'token_type' => 'Bearer',
|
2017-05-05 00:46:59 +03:00
|
|
|
'expires_in' => 3600,
|
|
|
|
'refresh_token' => $newCode,
|
2017-05-18 16:16:50 +03:00
|
|
|
'user_id' => $this->defaultTokenMapper->getTokenById($accessToken->getTokenId())->getUID(),
|
2017-05-05 00:46:59 +03:00
|
|
|
]
|
|
|
|
);
|
|
|
|
}
|
|
|
|
}
|