1.1.2
π UPC 1.1.2
Additive release exposing the OpenID Connect id_token on TokenOutput, so a consuming plugin can
identify who authorized a connection β not just which account the resulting token authorizes.
No breaking changes; a plugin that upgrades and changes nothing is unaffected.
β¨ Added
- πͺͺ
TokenOutput::$idTokenβ theid_tokenreturned by an authorization-code exchange, the only
place a logged-in person's identity surfaces.GET /accountcarries no email (its payload is
id,company_ref,country,object,is_live,configuration,permissions,
payment_methodsand nothing else, verified live against several QA accounts), and the
client_credentialstoken authenticates a machine, so it names no user either. A consumer wanting
the merchant's address has to read theemailclaim off this token at login time. - π
OAuth2Client::requestToken()passesid_tokenthrough when the token-endpoint response
carries one, instead of discarding it while constructing theTokenOutput.
β»οΈ Changed
- Nothing behavioural.
idTokenis a trailing 4th constructor argument defaulting tonull, and
a purely additive public property β every pre-existing 3-argument caller and every read of
accessToken/expiresIn/tokenTypeis untouched. idTokenis deliberately optional and unvalidated:requestToken()is shared by
exchangeAuthorizationCode()andgetClientCredentialsToken(), and only the former can ever
produce anid_token, so asserting on it would reject a perfectly usable client-credentials
response. UPC does not parse the JWT β consumers decode whichever claim they need.
π Compatibility
Upgrading from 1.1.x with no plugin-side change is a no-op:
TokenOutputisfinal, so nothing can have subclassed it with a 3-argument constructor.- The new read is
isset($data['id_token']) && \is_string(...)β it cannot throw and adds no failure
path. - No cache invalidation needed.
TokenManagercaches only the bare access-token string, never
the object, so the token-cache format is unchanged. Nothing in UPC serializes,json_encodes or
get_object_vars()aTokenOutput. idTokenis non-null only when a caller usesexchangeAuthorizationCode()and passes a scope
containingopenid/email; theclient_credentialsgrant always yieldsnull.
TokenOutput for
debugging (print_r, var_dump, json_encode, or a logger that serializes context objects) will now
see an id_token in that output where nothing appeared before β and an id_token is a JWT carrying PII
(email, sub). No current consumer does this, and it affects only the authorization-code path.
β Quality
PHPStan level 8, PHP-CS-Fixer, PHPUnit, and CI verifying PHP 7.1β8.2 compatibility β all clean on this
release branch. Six unit tests added: three on the value object (assignment, the null default, and
one asserting the constructor explicitly does not validate idToken) and three on OAuth2Client
(surfaced from an authorization-code response, left null when absent, left null for
client_credentials). The last two guard the optionality β they fail the day someone makes id_token
required in the shared requestToken(). make verify-71 passes; the new nullable type hint is 7.1
syntax.
π¦ Consumers
- Sylius plugin PRE-3631 pins
^1.1.2β it displays the connected PayPlug account's email on the
gateway-configuration admin screen, which is impossible on 1.1.0/1.1.1.
π Requirements
- PHP β₯7.4 to install/develop (build-tooling floor only β shipped source runs on PHP 7.1)
- Runtime dependency:
giggsey/libphonenumber-for-php
π Full Changelog: 1.1.1...1.1.2