-
Notifications
You must be signed in to change notification settings - Fork 785
/
Copy pathAuthorizationController.php
150 lines (128 loc) · 5.08 KB
/
AuthorizationController.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
<?php
namespace Laravel\Passport\Http\Controllers;
use Illuminate\Contracts\Auth\Authenticatable;
use Illuminate\Contracts\Auth\StatefulGuard;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Date;
use Illuminate\Support\Str;
use Laravel\Passport\Bridge\User;
use Laravel\Passport\Client;
use Laravel\Passport\ClientRepository;
use Laravel\Passport\Contracts\AuthorizationViewResponse;
use Laravel\Passport\Exceptions\AuthenticationException;
use Laravel\Passport\Exceptions\OAuthServerException;
use Laravel\Passport\Passport;
use League\OAuth2\Server\AuthorizationServer;
use League\OAuth2\Server\Entities\ScopeEntityInterface;
use League\OAuth2\Server\RequestTypes\AuthorizationRequestInterface;
use Psr\Http\Message\ResponseInterface;
use Psr\Http\Message\ServerRequestInterface;
use Symfony\Component\HttpFoundation\Response;
class AuthorizationController
{
use ConvertsPsrResponses, HandlesOAuthErrors;
/**
* Create a new controller instance.
*/
public function __construct(
protected AuthorizationServer $server,
protected StatefulGuard $guard,
protected ClientRepository $clients
) {
}
/**
* Authorize a client to access the user's account.
*/
public function authorize(
ServerRequestInterface $psrRequest,
Request $request,
ResponseInterface $psrResponse,
AuthorizationViewResponse $viewResponse
): Response|AuthorizationViewResponse {
$authRequest = $this->withErrorHandling(
fn (): AuthorizationRequestInterface => $this->server->validateAuthorizationRequest($psrRequest),
($psrRequest->getQueryParams()['response_type'] ?? null) === 'token'
);
if ($this->guard->guest()) {
$request->get('prompt') === 'none'
? throw OAuthServerException::loginRequired($authRequest)
: $this->promptForLogin($request);
}
if ($request->get('prompt') === 'login' &&
! $request->session()->get('promptedForLogin', false)) {
$this->guard->logout();
$request->session()->invalidate();
$request->session()->regenerateToken();
$this->promptForLogin($request);
}
$request->session()->forget('promptedForLogin');
$user = $this->guard->user();
$authRequest->setUser(new User($user->getAuthIdentifier()));
$scopes = $this->parseScopes($authRequest);
$client = $this->clients->find($authRequest->getClient()->getIdentifier());
if ($request->get('prompt') !== 'consent' &&
($client->skipsAuthorization($user, $scopes) || $this->hasGrantedScopes($user, $client, $scopes))) {
return $this->approveRequest($authRequest, $psrResponse);
}
if ($request->get('prompt') === 'none') {
throw OAuthServerException::consentRequired($authRequest);
}
$request->session()->put('authToken', $authToken = Str::random());
$request->session()->put('authRequest', $authRequest);
return $viewResponse->withParameters([
'client' => $client,
'user' => $user,
'scopes' => $scopes,
'request' => $request,
'authToken' => $authToken,
]);
}
/**
* Transform the authorization request's scopes into Scope instances.
*
* @return \Laravel\Passport\Scope[]
*/
protected function parseScopes(AuthorizationRequestInterface $authRequest): array
{
return Passport::scopesFor(
collect($authRequest->getScopes())->map(
fn (ScopeEntityInterface $scope): string => $scope->getIdentifier()
)->unique()->all()
);
}
/**
* Determine if the given user has already granted the client access to the scopes.
*
* @param \Laravel\Passport\Scope[] $scopes
*/
protected function hasGrantedScopes(Authenticatable $user, Client $client, array $scopes): bool
{
$tokensScopes = $client->tokens()->where([
['user_id', '=', $user->getAuthIdentifier()],
['revoked', '=', false],
['expires_at', '>', Date::now()],
])->pluck('scopes');
return $tokensScopes->isNotEmpty() &&
collect($scopes)->pluck('id')->diff($tokensScopes->flatten())->isEmpty();
}
/**
* Approve the authorization request.
*/
protected function approveRequest(AuthorizationRequestInterface $authRequest, ResponseInterface $psrResponse): Response
{
$authRequest->setAuthorizationApproved(true);
return $this->withErrorHandling(fn () => $this->convertResponse(
$this->server->completeAuthorizationRequest($authRequest, $psrResponse)
), $authRequest->getGrantTypeId() === 'implicit');
}
/**
* Prompt the user to login by throwing an AuthenticationException.
*
* @throws \Laravel\Passport\Exceptions\AuthenticationException
*/
protected function promptForLogin(Request $request): never
{
$request->session()->put('promptedForLogin', true);
throw new AuthenticationException;
}
}