Final Class Yiisoft\Yii\AuthClient\Client\OpenIdConnect
OpenIdConnect serves as a client for the OpenIdConnect flow.
See also Yiisoft\
Protected Properties
| Property | Type | Description | Defined By |
|---|---|---|---|
| $accessToken | array|Yiisoft\ |
Access token instance or its array configuration. | Yiisoft\ |
| $authParams | array | Additional auth GET params, merged into every {@see \ |
Yiisoft\ |
| $authUrl | string | Authorize URL. | Yiisoft\ |
| $autoRefreshAccessToken | boolean | Whether to automatically perform 'refresh access token' request on expired access token. | Yiisoft\ |
| $clientId | string | OAuth client ID. | Yiisoft\ |
| $clientSecret | string | OAuth client secret. | Yiisoft\ |
| $endpoint | string | API base URL. | Yiisoft\ |
| $environment | string | Environment identifier (e.g. 'dev' or 'prod'), for providers whose endpoint URLs differ by environment. | Yiisoft\ |
| $factory | \ |
Yiisoft\ |
|
| $httpClient | \ |
Yiisoft\ |
|
| $logo | string|null | SVG markup for the client's logo icon (e.g. brand glyph). | Yiisoft\ |
| $name | string | Custom name, set from the config array key. | Yiisoft\ |
| $normalizeUserAttributeMap | array | Map used to normalize user attributes fetched from external auth service in format: normalizedAttributeName => sourceSpecification 'sourceSpecification' can be: - string, raw attribute name - array, pass to raw attribute value - callable, PHP callback, which should accept array of raw attributes and return normalized value. | Yiisoft\ |
| $requestFactory | \ |
Yiisoft\ |
|
| $returnUrl | string | Yiisoft\ |
|
| $scope | ?string | Yiisoft\ |
|
| $session | \ |
Yiisoft\ |
|
| $title | string | Custom title, overrides the class default if set. | Yiisoft\ |
| $tokenUrl | string | Token request URL endpoint. | Yiisoft\ |
| $validateAuthState | boolean | Whether to use and validate auth 'state' parameter in authentication flow. | Yiisoft\ |
| $viewOptions | array | View options in format: optionName => optionValue | Yiisoft\ |
Public Methods
Protected Methods
| Method | Description | Defined By |
|---|---|---|
| applyClientCredentialsToRequest() | Yiisoft\ |
|
| createToken() | Yiisoft\ |
|
| createTokenRequest() | Builds a POST request to {@see tokenUrl} with $params as an application/x-www-form-urlencoded
body. RFC 6749 §4.1.3 requires token-endpoint parameters in the request body, not the URI query
string - a strict provider like Google rejects a query-string-only request outright (with no
usable access_token in its error response), while a lenient one like GitHub's legacy endpoint
happens to tolerate it. {@see applyClientCredentialsToRequest()} is expected to append further
params to this same body afterward, not build a request of its own. |
Yiisoft\ |
| defaultNormalizeUserAttributeMap() | Returns the default {@see normalizeUserAttributeMap} value. | Yiisoft\ |
| defaultReturnUrl() | Yiisoft\ |
|
| defaultViewOptions() | Yiisoft\ |
|
| fetchCurrentUserJsonArray() | Fetches current user data as JSON array from the given endpoint, authenticating the request with
the access token as an Authorization header. |
Yiisoft\ |
| generateAuthNonce() | Generates the auth nonce value. | Yiisoft\ |
| generateAuthState() | Generates the auth state value. | Yiisoft\ |
| generateAuthStateBaseString() | Builds the seed string used by {@see generateAuthState()}. Extracted into its own method so the seed's composition can be tested directly, since the final hashed/uniqid()-mixed auth state value is opaque and can't reveal how its input was assembled. | Yiisoft\ |
| getDefaultScope() | Yiisoft\ |
|
| getJwkSet() | Yiisoft\ |
|
| getJwsLoader() | Returns the JWSLoader that validates the JWS token. | Yiisoft\ |
| getState() | Returns persistent state value. | Yiisoft\ |
| getStateKeyPrefix() | Returns session key prefix, which is used to store internal states. | Yiisoft\ |
| initUserAttributes() | Yiisoft\ |
|
| loadJws() | Decrypts/validates JWS, returning related data. | Yiisoft\ |
| removeState() | Removes persistent state value. | Yiisoft\ |
| restoreAccessToken() | Restores access token. | Yiisoft\ |
| saveAccessToken() | Saves token as persistent state. | Yiisoft\ |
| sendRequest() | Yiisoft\ |
|
| setState() | Sets persistent state. | Yiisoft\ |
| validateClaims() | Validates the claims data received from the OpenID provider. | Yiisoft\ |
Property Details
Method Details
| public mixed __construct ( \ | ||
| $httpClient | \ |
|
| $requestFactory | \ |
|
| $stateStorage | Yiisoft\ |
|
| $factory | \ |
|
| $session | \ |
|
| $cache | \ |
|
public function __construct(
ClientInterface $httpClient,
RequestFactoryInterface $requestFactory,
StateStorageInterface $stateStorage,
Factory $factory,
SessionInterface $session,
private readonly CacheInterface $cache,
) {
parent::__construct($httpClient, $requestFactory, $stateStorage, $factory, $session);
}
Defined in:
Yiisoft\
Performs request to the OAuth API returning response data.
You may use {@see \
See also createApiRequest().
| public array api ( string $apiSubUrl, string $method = 'GET', array|string $data = [], array $headers = [] ) | ||
| $apiSubUrl | string |
API sub URL, which will be append to {@see \ |
| $method | string |
Request method. |
| $data | array|string |
Request data or content. |
| $headers | array |
Additional request headers. |
| return | array |
API response data. |
|---|---|---|
| throws | Exception | |
public function api($apiSubUrl, $method = 'GET', $data = [], $headers = []): array
{
$request = $this->createApiRequest($method, $apiSubUrl);
$request = RequestUtil::addHeaders($request, $headers);
if (!empty($data)) {
if (is_array($data)) {
$request = RequestUtil::addParams($request, $data);
} else {
$request->getBody()->write($data);
}
}
$request = $this->beforeApiRequestSend($request);
$response = $this->sendRequest($request);
if ($response->getStatusCode() !== 200) {
throw new InvalidResponseException(
$response,
'Request failed with code: ' . $response->getStatusCode() . ', message: ' . $response->getBody(),
);
}
return (array) Json::decode($response->getBody()->getContents());
}
| public \ | ||
| $request | \ |
|
| $accessToken | Yiisoft\ |
|
public function applyAccessTokenToRequest(RequestInterface $request, OAuthToken $accessToken): RequestInterface
{
return RequestUtil::addParams(
$request,
[
'access_token' => $accessToken->getToken(),
],
);
}
| protected \ | ||
| $request | \ |
|
protected function applyClientCredentialsToRequest(RequestInterface $request): RequestInterface
{
$supportedAuthMethods = (array) $this->getConfigParam('token_endpoint_auth_methods_supported');
if (in_array('client_secret_basic', $supportedAuthMethods, true)) {
return $this->applyClientSecretBasic($request);
}
if (in_array('client_secret_post', $supportedAuthMethods, true)) {
return $this->applyClientSecretPost($request);
}
if (in_array('client_secret_jwt', $supportedAuthMethods, true)) {
return $this->applyClientSecretJwt($request);
}
throw new InvalidConfigException('Unable to authenticate request: No auth method supported');
}
| public \ | ||
| $request | \ |
|
public function beforeApiRequestSend(RequestInterface $request): RequestInterface
{
$accessToken = $this->getAccessToken();
if (!is_object($accessToken) || !$accessToken->getIsValid()) {
throw new Exception('Invalid access token.');
}
return $this->applyAccessTokenToRequest($request, $accessToken);
}
| public string buildAuthUrl ( \ | ||
| $incomingRequest | \ |
|
| $params | array | |
public function buildAuthUrl(ServerRequestInterface $incomingRequest, array $params = []): string
{
if (empty($this->authUrl)) {
$this->authUrl = (string) $this->getConfigParam('authorization_endpoint');
}
return parent::buildAuthUrl($incomingRequest, $params);
}
Defined in:
Yiisoft\
Creates an HTTP request for the API call.
The created request will be automatically processed adding access token parameters and signature
before sending. You may use {@see \
See also createRequest().
| public \ | ||
| $method | string | |
| $uri | string | |
| return | \ |
HTTP request instance. |
|---|---|---|
public function createApiRequest(string $method, string $uri): RequestInterface
{
return $this->createRequest($method, $this->endpoint . $uri);
}
| public \ | ||
| $method | string | |
| $uri | string | |
public function createRequest(string $method, string $uri): RequestInterface
{
return $this->requestFactory->createRequest($method, $uri);
}
| protected Yiisoft\ | ||
| $tokenConfig | array | |
protected function createToken(array $tokenConfig = []): OAuthToken
{
$params = (array) $tokenConfig['params'];
$idToken = (string) ($params['id_token'] ?? '');
if ($this->validateJws) {
$jwsData = $this->loadJws($idToken);
$this->validateClaims($jwsData);
$tokenConfig['params'] = array_merge($params, $jwsData);
if ($this->getValidateAuthNonce()) {
$nonce = isset($jwsData['nonce']) ? (string) $jwsData['nonce'] : '';
$authNonce = (string) $this->getState('authNonce');
if (!isset($jwsData['nonce']) || empty($authNonce) || strcmp($nonce, $authNonce) !== 0) {
throw new ClientException('Invalid auth nonce', 400);
}
$this->removeState('authNonce');
}
}
return parent::createToken($tokenConfig);
}
Defined in:
Yiisoft\
Builds a POST request to {@see tokenUrl} with $params as an application/x-www-form-urlencoded
body. RFC 6749 §4.1.3 requires token-endpoint parameters in the request body, not the URI query
string - a strict provider like Google rejects a query-string-only request outright (with no
usable access_token in its error response), while a lenient one like GitHub's legacy endpoint
happens to tolerate it. {@see applyClientCredentialsToRequest()} is expected to append further
params to this same body afterward, not build a request of its own.
| protected \ | ||
| $params | array | |
protected function createTokenRequest(array $params): RequestInterface
{
$request = $this->createRequest('POST', $this->tokenUrl)
->withHeader('Content-Type', 'application/x-www-form-urlencoded');
$request->getBody()->write(http_build_query($params, arg_separator: '&', encoding_type: PHP_QUERY_RFC3986));
return $request;
}
Defined in:
Yiisoft\
Returns the default {@see normalizeUserAttributeMap} value.
Particular client may override this method in order to provide specific default map.
| protected array defaultNormalizeUserAttributeMap ( ) | ||
| return | array |
Normalize attribute map. |
|---|---|---|
protected function defaultNormalizeUserAttributeMap(): array
{
return [];
}
| protected string defaultReturnUrl ( \ | ||
| $request | \ |
|
protected function defaultReturnUrl(ServerRequestInterface $request): string
{
$params = $request->getQueryParams();
unset($params['code'], $params['state'], $params['nonce'], $params['authuser'], $params['session_state'], $params['prompt']);
return (string) $request->getUri()->withQuery(
http_build_query($params, arg_separator: '&', encoding_type: PHP_QUERY_RFC3986),
);
}
| protected integer[] defaultViewOptions ( ) |
protected function defaultViewOptions(): array
{
return [
'popupWidth' => 860,
'popupHeight' => 480,
];
}
| public Yiisoft\ | ||
| $incomingRequest | \ |
|
| $authCode | string | |
| $params | array | |
public function fetchAccessToken(ServerRequestInterface $incomingRequest, string $authCode, array $params = []): OAuthToken
{
$this->resolveTokenUrl();
if (!isset($params['nonce']) && $this->getValidateAuthNonce()) {
$nonce = $this->generateAuthNonce();
$this->setState('authNonce', $nonce);
$params['nonce'] = $nonce;
}
return parent::fetchAccessToken($incomingRequest, $authCode, $params);
}
Defined in:
Yiisoft\
Note: This function will be adapted later to accomodate the 'confidential client'.
See also https://docs.x.com/resources/fundamentals/authentication/oauth-2-0/authorization-code Used specifically for the X i.e. Twitter OAuth2.0 Authorization code with PKCE and public client i.e. client id included in request body; and NOT Confidential Client i.e. Client id not included in the request body.
| public Yiisoft\ | ||
| $incomingRequest | \ |
|
| $authCode | string | |
| $params | array | |
| throws | InvalidArgumentException | |
|---|---|---|
public function fetchAccessTokenWithCodeVerifier(
ServerRequestInterface $incomingRequest,
string $authCode,
array $params = [],
): OAuthToken {
if ($this->validateAuthState) {
/**
* @var string|null $authState 'authState' is only ever written by
* {@see buildAuthUrl()} with the string returned from {@see generateAuthState()}.
*/
$authState = $this->getState('authState');
$queryParams = $incomingRequest->getQueryParams();
$bodyParams = $incomingRequest->getParsedBody();
/**
* @psalm-suppress MixedAssignment
*/
$incomingState = $queryParams['state'] ?? ($bodyParams['state'] ?? null);
if (is_string($incomingState)) {
if (strcmp($incomingState, (string) $authState) !== 0) {
throw new InvalidArgumentException('Invalid auth state parameter.');
}
}
if ($incomingState === null) {
throw new InvalidArgumentException('Invalid auth state parameter.');
}
if (empty($authState)) {
throw new InvalidArgumentException('Invalid auth state parameter.');
}
$this->removeState('authState');
}
$requestBody = [
'code' => $authCode,
'grant_type' => 'authorization_code',
'client_id' => $this->clientId,
'client_secret' => $this->clientSecret,
'redirect_uri' => $params['redirect_uri'] ?? '',
'code_verifier' => $params['code_verifier'] ?? '',
];
$request = $this->requestFactory
->createRequest('POST', $this->tokenUrl)
->withHeader(Header::CONTENT_TYPE, 'application/x-www-form-urlencoded');
$request->getBody()->write(
http_build_query($requestBody, arg_separator: '&', encoding_type: PHP_QUERY_RFC3986),
);
try {
$response = $this->httpClient->sendRequest($request);
$body = $response->getBody()->getContents();
$output = (array) Json::decode($body);
} catch (Throwable) {
$output = [];
}
$token = $this->createToken(['params' => $output]);
$this->setAccessToken($token);
return $token;
}
Defined in:
Yiisoft\
Fetches current user data as JSON array from the given endpoint, authenticating the request with
the access token as an Authorization header.
| protected array fetchCurrentUserJsonArray ( Yiisoft\ | ||
| $token | Yiisoft\ |
Access token, whose |
| $url | string |
Endpoint URL to fetch user data from. |
| $headers | array |
Additional request headers, merged over the default |
| $authScheme | string |
|
| return | array |
Decoded user data, or an empty array if there is no access token or the request fails. |
|---|---|---|
protected function fetchCurrentUserJsonArray(
OAuthToken $token,
string $url,
array $headers = [],
string $authScheme = 'Bearer',
): array {
$tokenString = (string) $token->getParam('access_token');
if ($tokenString === '') {
return [];
}
$request = RequestUtil::addHeaders(
$this->createRequest('GET', $url),
array_merge(['Authorization' => $authScheme . ' ' . $tokenString], $headers),
);
if ($request->getHeaderLine('User-Agent') === '') {
$request = $request->withHeader('User-Agent', 'yiisoft/yii-auth-client');
}
try {
$body = $this->sendRequest($request)->getBody()->getContents();
} catch (Throwable) {
return [];
}
return $body === '' ? [] : (array) Json::decode($body);
}
Generates the auth nonce value.
| protected string generateAuthNonce ( ) | ||
| return | string |
Auth nonce value. |
|---|---|---|
| throws | Exception | |
protected function generateAuthNonce(): string
{
return Random::string();
}
Defined in:
Yiisoft\
Generates the auth state value.
| protected string generateAuthState ( ) | ||
| return | string |
Auth state value. |
|---|---|---|
protected function generateAuthState(): string
{
return hash('sha256', uniqid($this->generateAuthStateBaseString(), true));
}
Defined in:
Yiisoft\
Builds the seed string used by {@see generateAuthState()}. Extracted into its own method so the seed's composition can be tested directly, since the final hashed/uniqid()-mixed auth state value is opaque and can't reveal how its input was assembled.
| protected string generateAuthStateBaseString ( ) | ||
| return | string |
Auth state seed. |
|---|---|---|
protected function generateAuthStateBaseString(): string
{
$baseString = static::class . '-' . time();
$sessionId = $this->session->getId();
if (null !== $sessionId) {
if ($this->session->isActive()) {
$baseString .= '-' . $sessionId;
}
}
return $baseString;
}
Defined in:
Yiisoft\
| public Yiisoft\ | ||
| return | Yiisoft\ |
Auth token instance. |
|---|---|---|
public function getAccessToken(): ?OAuthToken
{
if (!is_object($this->accessToken)) {
$this->accessToken = $this->restoreAccessToken();
}
return $this->accessToken;
}
Defined in:
Yiisoft\
| public array getAuthParams ( ) |
public function getAuthParams(): array
{
return $this->authParams;
}
Defined in:
Yiisoft\
| public string getClientId ( ) |
public function getClientId(): string
{
return $this->clientId;
}
Defined in:
Yiisoft\
| public string getClientSecret ( ) |
public function getClientSecret(): string
{
return $this->clientSecret;
}
Returns particular configuration parameter value.
| public mixed getConfigParam ( string $name ) | ||
| $name | string |
Configuration parameter name. |
| return | mixed |
Configuration parameter value. |
|---|---|---|
| throws | Yiisoft\ |
|
| throws | \ |
|
public function getConfigParam(string $name): mixed
{
$params = $this->getConfigParams();
return $params[$name] ?? null;
}
| public array getConfigParams ( ) | ||
| return | array |
OpenID provider configuration parameters. |
|---|---|---|
| throws | Yiisoft\ |
|
| throws | \ |
|
public function getConfigParams(): array
{
if (empty($this->configParams)) {
$cacheKey = $this->cacheKeyPrefix . $this->getName();
$configParams = (array) $this->cache->get($cacheKey);
if (empty($configParams)) {
$configParams = $this->discoverConfig();
$this->cache->set($cacheKey, $configParams);
}
$this->configParams = $configParams;
}
return $this->configParams;
}
| public array getCurrentUserJsonArray ( Yiisoft\ | ||
| $oauthToken | Yiisoft\ |
|
public function getCurrentUserJsonArray(OAuthToken $oauthToken): array
{
return $this->fetchCurrentUserJsonArray($oauthToken, (string) $this->getConfigParam('userinfo_endpoint'));
}
Defined in:
Yiisoft\
| protected string getDefaultScope ( ) |
protected function getDefaultScope(): string
{
return '';
}
| protected ?\ |
protected function getJwkSet(): ?JWKSet
{
if ($this->jwkSet instanceof JWKSet) {
return $this->jwkSet;
}
$cacheKey = $this->cacheKeyPrefix . 'jwkSet';
/** @var mixed $jwkSetRaw */
$jwkSetRaw = $this->cache->get($cacheKey);
/** @var JWKSet|null $jwkSet */
$jwkSet = $jwkSetRaw instanceof JWKSet ? $jwkSetRaw : null;
if ($jwkSet === null) {
/** @var mixed $jwksUriRaw */
$jwksUriRaw = $this->getConfigParam('jwks_uri');
$jwksUri = is_string($jwksUriRaw) ? $jwksUriRaw : '';
$request = $this->createRequest('GET', $jwksUri);
$response = $this->sendRequest($request);
/** @var mixed $jsonBody */
$jsonBody = Json::decode($response->getBody()->getContents());
$jsonBody = is_array($jsonBody) ? $jsonBody : [];
/** @var mixed $fetched */
$fetched = JWKFactory::createFromValues($jsonBody);
$this->cache->set($cacheKey, $fetched);
// JWKFactory::createFromValues() may return a plain JWK (single-key response)
// instead of a JWKSet; $this->jwkSet is strictly typed, so only a real JWKSet is kept.
$jwkSet = $fetched instanceof JWKSet ? $fetched : null;
}
if ($jwkSet instanceof JWKSet) {
$this->jwkSet = $jwkSet;
}
return $jwkSet;
}
Returns the JWSLoader that validates the JWS token.
| protected \ | ||
| return | \ |
To do token validation. |
|---|---|---|
| throws | Yiisoft\ |
on an invalid algorithm provided in the configuration. |
protected function getJwsLoader(): JWSLoader
{
if (!($this->jwsLoader instanceof JWSLoader)) {
$algorithms = [];
/** @var string $algorithm */
foreach ($this->allowedJwsAlgorithms as $algorithm) {
/** @var class-string<Algorithm> $class */
$class = '\Jose\Component\Signature\Algorithm\\' . $algorithm;
if (!class_exists($class)) {
throw new InvalidConfigException("Algorithm class $class doesn't exist");
}
$algorithms[] = new $class();
}
$algorithmManager = new AlgorithmManager($algorithms);
$compactSerializer = new CompactSerializer();
/** @psalm-var string[] $this->allowedJwsAlgorithms */
$checker = new AlgorithmChecker($this->allowedJwsAlgorithms);
$this->jwsLoader = new JWSLoader(
new JWSSerializerManager([$compactSerializer]),
new JWSVerifier($algorithmManager),
/**
* @infection-ignore-all
* $checker enforces the same $allowedJwsAlgorithms list that $algorithmManager above
* is built from, so JWSVerifier already rejects any "alg" this checker would reject;
* dropping it from the array is behaviorally unobservable from the outside.
*/
new HeaderCheckerManager(
[$checker],
[new JWSTokenSupport()],
),
);
}
return $this->jwsLoader;
}
Defined in:
Yiisoft\
| public ?string getLogo ( ) |
public function getLogo(): ?string
{
return $this->logo;
}
| public string getName ( ) |
public function getName(): string
{
return $this->name ?: 'openid-connect';
}
| public array getNormalizeUserAttributeMap ( ) | ||
| return | array |
Normalize user attribute map. |
|---|---|---|
public function getNormalizeUserAttributeMap(): array
{
if (empty($this->normalizeUserAttributeMap)) {
$this->normalizeUserAttributeMap = $this->defaultNormalizeUserAttributeMap();
}
return $this->normalizeUserAttributeMap;
}
| public string getOauth2ReturnUrl ( ) |
public function getOauth2ReturnUrl(): string
{
return $this->returnUrl;
}
| public \ |
public function getRequestFactory(): RequestFactoryInterface
{
return $this->requestFactory;
}
Defined in:
Yiisoft\
| public string getReturnUrl ( \ | ||
| $request | \ |
|
| return | string |
Return URL. |
|---|---|---|
public function getReturnUrl(ServerRequestInterface $request): string
{
if ($this->returnUrl === '') {
$this->returnUrl = $this->defaultReturnUrl($request);
}
return $this->returnUrl;
}
Defined in:
Yiisoft\
| public string getScope ( ) |
public function getScope(): string
{
if ($this->scope === null) {
return $this->getDefaultScope();
}
return $this->scope;
}
Defined in:
Yiisoft\
Compare a callback query parameter 'state' with the saved Auth Client's 'authState' parameter in order to prevent CSRF attacks
Use: Typically used in a AuthController's callback function specifically for an Identity Provider e.g. Facebook
| public mixed getSessionAuthState ( ) |
public function getSessionAuthState(): mixed
{
/**
* @see src\AuthClient protected function getState('authState')
*/
return $this->getState('authState');
}
Defined in:
Yiisoft\
Returns persistent state value.
| protected mixed getState ( string $key ) | ||
| $key | string |
State key. |
| return | mixed |
State value. |
|---|---|---|
protected function getState(string $key): mixed
{
return $this->stateStorage->get($this->getStateKeyPrefix() . $key);
}
Defined in:
Yiisoft\
Returns session key prefix, which is used to store internal states.
| protected string getStateKeyPrefix ( ) | ||
| return | string |
Session key prefix. |
|---|---|---|
protected function getStateKeyPrefix(): string
{
return static::class . '_' . $this->getName() . '_';
}
| public string getTitle ( ) |
public function getTitle(): string
{
if ($this->title !== '') {
return $this->title;
}
return $this->name !== '' ? ucfirst($this->name) : 'OpenID Connect';
}
Defined in:
Yiisoft\
| public string getTokenUrl ( ) |
public function getTokenUrl(): string
{
return $this->tokenUrl;
}
Defined in:
Yiisoft\
Returns the authenticated user's attributes, as fetched by {@see initUserAttributes()} and normalized according to {@see normalizeUserAttributeMap}.
| public array getUserAttributes ( ) | ||
| return | array |
User attributes. |
|---|---|---|
public function getUserAttributes(): array
{
$attributes = $this->initUserAttributes();
$normalizeMap = $this->getNormalizeUserAttributeMap();
return array_merge($attributes, $this->normalizeUserAttributes($attributes, $normalizeMap));
}
| public boolean getValidateAuthNonce ( ) | ||
| return | boolean |
Whether to use and validate auth 'nonce' parameter in authentication flow. |
|---|---|---|
| throws | Yiisoft\ |
|
| throws | \ |
|
public function getValidateAuthNonce(): bool
{
if ($this->validateAuthNonce === null) {
$this->validateAuthNonce = $this->validateJws && in_array(
'nonce',
(array) $this->getConfigParam('claims_supported'),
true,
);
}
return $this->validateAuthNonce;
}
| public array getViewOptions ( ) | ||
| return | array |
View options in format: optionName => optionValue |
|---|---|---|
public function getViewOptions(): array
{
if (empty($this->viewOptions)) {
$this->viewOptions = $this->defaultViewOptions();
}
return $this->viewOptions;
}
| public \ |
public function getYiisoftFactory(): YiisoftFactory
{
return $this->factory;
}
| protected array initUserAttributes ( ) |
protected function initUserAttributes(): array
{
$token = $this->getAccessToken();
if ($token instanceof OAuthToken) {
return $this->getCurrentUserJsonArray($token);
}
return [];
}
Decrypts/validates JWS, returning related data.
| protected array loadJws ( string $jws ) | ||
| $jws | string |
Raw JWS input. |
| return | array |
JWS underlying data. |
|---|---|---|
| throws | Yiisoft\ |
on invalid JWS signature. |
protected function loadJws(string $jws): array
{
try {
$jwsLoader = $this->getJwsLoader();
$signature = null;
$jwkSet = $this->getJwkSet();
if ($jwkSet === null) {
throw new ClientException('JWK Set is not available.', 400);
}
$jwsVerified = $jwsLoader->loadAndVerifyWithKeySet($jws, $jwkSet, $signature);
return (array) Json::decode((string) $jwsVerified->getPayload());
} catch (Exception $e) {
throw new ClientException('Loading JWS: Exception: ' . $e->getMessage(), (int) $e->getCode());
}
}
| public Yiisoft\ | ||
| $token | Yiisoft\ |
|
public function refreshAccessToken(OAuthToken $token): OAuthToken
{
$this->resolveTokenUrl();
return parent::refreshAccessToken($token);
}
Defined in:
Yiisoft\
Removes persistent state value.
| protected void removeState ( string $key ) | ||
| $key | string |
State key. |
protected function removeState(string $key): void
{
$this->stateStorage->remove($this->getStateKeyPrefix() . $key);
}
Defined in:
Yiisoft\
Restores access token.
| protected Yiisoft\ |
protected function restoreAccessToken(): ?OAuthToken
{
if (($token = $this->getState('token')) instanceof OAuthToken) {
if ($token->getIsExpired() && $this->autoRefreshAccessToken) {
return $this->refreshAccessToken($token);
}
return $token;
}
return null;
}
Defined in:
Yiisoft\
Saves token as persistent state.
| protected $this saveAccessToken ( Yiisoft\ | ||
| $token | Yiisoft\ |
Auth token to be saved. |
| return | $this |
The object itself. |
|---|---|---|
protected function saveAccessToken(?OAuthToken $token = null): self
{
return $this->setState('token', $token);
}
Defined in:
Yiisoft\
| protected \ | ||
| $request | \ |
|
protected function sendRequest(RequestInterface $request): ResponseInterface
{
return $this->httpClient->sendRequest($request);
}
Defined in:
Yiisoft\
Sets access token to be used.
| public void setAccessToken ( array|Yiisoft\ | ||
| $token | array|Yiisoft\ |
Access token or its configuration. |
public function setAccessToken(array|OAuthToken $token): void
{
if (is_array($token) && !empty($token)) {
$newToken = $this->createToken($token);
$this->accessToken = $newToken;
$this->saveAccessToken($newToken);
}
if ($token instanceof OAuthToken) {
$this->accessToken = $token;
$this->saveAccessToken($token);
}
}
Defined in:
Yiisoft\
| public void setAuthParams ( array $authParams ) | ||
| $authParams | array | |
public function setAuthParams(array $authParams): void
{
$this->authParams = $authParams;
}
Defined in:
Yiisoft\
| public void setAuthUrl ( string $authUrl ) | ||
| $authUrl | string | |
public function setAuthUrl(string $authUrl): void
{
$this->authUrl = $authUrl;
}
Defined in:
Yiisoft\
| public void setClientId ( string $clientId ) | ||
| $clientId | string | |
public function setClientId(string $clientId): void
{
$this->clientId = $clientId;
}
Defined in:
Yiisoft\
| public void setClientSecret ( string $clientSecret ) | ||
| $clientSecret | string | |
public function setClientSecret(string $clientSecret): void
{
$this->clientSecret = $clientSecret;
}
Defined in:
Yiisoft\
| public void setEnvironment ( string $devOrProd ) | ||
| $devOrProd | string | |
public function setEnvironment(string $devOrProd): void
{
$this->environment = $devOrProd;
}
| public void setIssuerUrl ( string $url ) | ||
| $url | string | |
public function setIssuerUrl(string $url): void
{
$this->issuerUrl = rtrim($url, '/');
}
Defined in:
Yiisoft\
| public void setLogo ( ?string $logo ) | ||
| $logo | ?string | |
public function setLogo(?string $logo): void
{
$this->logo = $logo;
}
Defined in:
Yiisoft\
| public void setName ( string $name ) | ||
| $name | string | |
public function setName(string $name): void
{
$this->name = $name;
}
| public void setOauth2ReturnUrl ( string $returnUrl ) | ||
| $returnUrl | string | |
public function setOauth2ReturnUrl(string $returnUrl): void
{
$this->returnUrl = $returnUrl;
}
| public void setRequestFactory ( \ | ||
| $requestFactory | \ |
|
public function setRequestFactory(RequestFactoryInterface $requestFactory): void
{
$this->requestFactory = $requestFactory;
}
Defined in:
Yiisoft\
| public void setReturnUrl ( string $returnUrl ) | ||
| $returnUrl | string |
Return URL |
public function setReturnUrl(string $returnUrl): void
{
$this->returnUrl = $returnUrl;
}
Defined in:
Yiisoft\
| public void setScope ( string $scope ) | ||
| $scope | string |
Auth request scope, overriding {@see \ |
public function setScope(string $scope): void
{
$this->scope = $scope;
}
Defined in:
Yiisoft\
Sets persistent state.
| protected $this setState ( string $key, mixed $value ) | ||
| $key | string |
State key. |
| $value | mixed |
State value |
| return | $this |
The object itself |
|---|---|---|
protected function setState(string $key, $value): self
{
$this->stateStorage->set($this->getStateKeyPrefix() . $key, $value);
return $this;
}
Defined in:
Yiisoft\
| public void setTitle ( string $title ) | ||
| $title | string | |
public function setTitle(string $title): void
{
$this->title = $title;
}
Defined in:
Yiisoft\
| public void setTokenUrl ( string $tokenUrl ) | ||
| $tokenUrl | string | |
public function setTokenUrl(string $tokenUrl): void
{
$this->tokenUrl = $tokenUrl;
}
| public void setValidateAuthNonce ( boolean $validateAuthNonce ) | ||
| $validateAuthNonce | boolean | |
public function setValidateAuthNonce(bool $validateAuthNonce): void
{
$this->validateAuthNonce = $validateAuthNonce;
}
| public void setYiisoftFactory ( \ | ||
| $factory | \ |
|
public function setYiisoftFactory(YiisoftFactory $factory): void
{
$this->factory = $factory;
}
Validates the claims data received from the OpenID provider.
| protected void validateClaims ( array $claims ) | ||
| $claims | array |
Claims data. |
| throws | Yiisoft\ |
on invalid claims. |
|---|---|---|
protected function validateClaims(array $claims): void
{
$iss = isset($claims['iss']) ? (string) $claims['iss'] : '';
$issuerUrl = $this->issuerUrl;
if (!isset($claims['iss']) || strcmp(rtrim($iss, '/'), rtrim($issuerUrl, '/')) !== 0) {
throw new ClientException('Invalid "iss"', 400);
}
try {
// "aud" may legally be a string or an array of strings (RFC 7519 §4.1.3); AudienceChecker
// handles both, unlike a plain string comparison which would reject a valid array audience.
(new AudienceChecker($this->clientId))->checkClaim($claims['aud'] ?? null);
} catch (InvalidClaimException) {
throw new ClientException('Invalid "aud"', 400);
}
}
| public self withValidateAuthState ( ) |
public function withValidateAuthState(): self
{
$new = clone $this;
$new->validateAuthState = true;
return $new;
}
Enables JWS validation/decryption of the auth token (the default). See {@see validateJws} for details.
| public self withValidateJws ( ) |
public function withValidateJws(): self
{
$new = clone $this;
$new->validateJws = true;
return $new;
}
| public self withoutValidateAuthState ( ) |
public function withoutValidateAuthState(): self
{
$new = clone $this;
$new->validateAuthState = false;
return $new;
}
Disables JWS validation/decryption of the auth token. See {@see validateJws} for the trade-offs of doing so.
| public self withoutValidateJws ( ) |
public function withoutValidateJws(): self
{
$new = clone $this;
$new->validateJws = false;
return $new;
}
User Contributed Notes
Leave a comment
Join the conversation to share a note.