-
Notifications
You must be signed in to change notification settings - Fork 148
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add additional support for jwt encryption
- Loading branch information
1 parent
0502481
commit ab916ed
Showing
9 changed files
with
541 additions
and
118 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,53 @@ | ||
<?php | ||
|
||
require 'vendor/autoload.php'; | ||
|
||
session_start(); | ||
|
||
$provider = new Stevenmaguire\OAuth2\Client\Provider\Keycloak([ | ||
'authServerUrl' => '', | ||
'realm' => '', | ||
'clientId' => '', | ||
'clientSecret' => '', | ||
'redirectUri' => '', | ||
'encryptionAlgorithm' => null, | ||
'encryptionKey' => null, | ||
'encryptionKeyPath' => null | ||
]); | ||
|
||
if (!isset($_GET['code'])) { | ||
// If we don't have an authorization code then get one | ||
$authUrl = $provider->getAuthorizationUrl(); | ||
$_SESSION['oauth2state'] = $provider->getState(); | ||
header('Location: '.$authUrl); | ||
exit; | ||
|
||
// Check given state against previously stored one to mitigate CSRF attack | ||
} elseif (empty($_GET['state']) || ($_GET['state'] !== $_SESSION['oauth2state'])) { | ||
unset($_SESSION['oauth2state']); | ||
exit('Invalid state, make sure HTTP sessions are enabled.'); | ||
} else { | ||
// Try to get an access token (using the authorization coe grant) | ||
try { | ||
$token = $provider->getAccessToken('authorization_code', [ | ||
'code' => $_GET['code'] | ||
]); | ||
} catch (Exception $e) { | ||
exit('Failed to get access token: '.$e->getMessage()); | ||
} | ||
|
||
// Optional: Now you have a token you can look up a users profile data | ||
try { | ||
|
||
// We got an access token, let's now get the user's details | ||
$user = $provider->getResourceOwner($token); | ||
// Use these details to create a new profile | ||
printf('Hello %s!\n<br>', $user->getName()); | ||
|
||
} catch (Exception $e) { | ||
exit('Failed to get resource owner: '.$e->getMessage()); | ||
} | ||
|
||
// Use this to interact with an API on the users behalf | ||
echo $token->getToken(); | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
10 changes: 10 additions & 0 deletions
10
src/Provider/Exception/EncryptionConfigurationException.php
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,10 @@ | ||
<?php | ||
|
||
namespace Stevenmaguire\OAuth2\Client\Provider\Exception; | ||
|
||
use Exception; | ||
|
||
class EncryptionConfigurationException extends Exception | ||
{ | ||
// nothing special here, just a name | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.